Sharpness-Aware Minimization Leads to Better Robustness in Meta-learning

被引:0
|
作者
Xu, Mengke [1 ]
Wang, Huiwei [2 ,3 ]
机构
[1] Southwest Univ, Coll Elect & Informat Engn, Chongqing 400715, Peoples R China
[2] Chongqing Three Gorges Univ, Key Lab Intelligent Informat Proc, Chongqing 404100, Peoples R China
[3] Beijing Inst Technol, Chongqing Innovat Ctr, Chongqing 401120, Peoples R China
来源
2023 15TH INTERNATIONAL CONFERENCE ON ADVANCED COMPUTATIONAL INTELLIGENCE, ICACI | 2023年
基金
中国博士后科学基金;
关键词
Meta-learning; R2D2; Sharpness-Aware Minimization;
D O I
10.1109/ICACI58115.2023.10146130
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Transforming few-shot learning into meta-learning is an important way to narrow the gap between human ability and machine learning. In this paper, we study the adversarial robustness of meta-learning model and propose Defending R2D2 algorithm (DeR2D2) to resist attacks. We pay more attention to the two problems of adversarial meta-learning: the high training cost and the significant decrease of classification accuracy on clean samples. First, we demonstrate that the introduction of adversarial samples in R2D2 training can improve its adversarial robustness. Second, we choose Randomized Fast Gradient Sign Method (R+FGSM) instead of Projected Gradient Descent (PGD) as the adversarial training method, which significantly reduces the training cost. Finally, due to the Sharpness-Aware Minimization (SAM), our method further reduces adversarial training time and significantly improves the classification accuracy on clean samples. In addition, we verify that in most cases, DeR2D2 also has a strong ability to defend against attacks.
引用
收藏
页数:8
相关论文
共 46 条
  • [1] Federated Model-Agnostic Meta-Learning With Sharpness-Aware Minimization for Internet of Things Optimization
    Wu, Qingtao
    Zhang, Yong
    Liu, Muhua
    Zhu, Junlong
    Zheng, Ruijuan
    Zhang, Mingchuan
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (19): : 31317 - 31330
  • [2] Enhancing Sharpness-Aware Minimization by Learning Perturbation Radius
    Wang, Xuehao
    Jiang, Weisen
    Fu, Shuai
    Zhang, Yu
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES: RESEARCH TRACK, PT II, ECML PKDD 2024, 2024, 14942 : 375 - 391
  • [3] Convergence of Sharpness-Aware Minimization with Momentum
    Pham Duy Khanh
    Luong, Hoang-Chau
    Mordukhovich, Boris S.
    Dat Ba Tran
    Truc Vo
    INFORMATION TECHNOLOGIES AND THEIR APPLICATIONS, PT II, ITTA 2024, 2025, 2226 : 123 - 132
  • [4] Sharpness-Aware Minimization and the Edge of Stability
    Long, Philip M.
    Bartlett, Peter L.
    JOURNAL OF MACHINE LEARNING RESEARCH, 2024, 25 : 1 - 20
  • [5] Noise-resistant sharpness-aware minimization in deep learning
    Su, Dan
    Jin, Long
    Wang, Jun
    NEURAL NETWORKS, 2025, 181
  • [6] Implicit Sharpness-Aware Minimization for Domain Generalization
    Dong, Mingrong
    Yang, Yixuan
    Zeng, Kai
    Wang, Qingwang
    Shen, Tao
    REMOTE SENSING, 2024, 16 (16)
  • [7] Sharpness-Aware Minimization Revisited: Weighted Sharpness as a Regularization Term
    Yue, Yun
    Jiang, Jiadi
    Ye, Zhiling
    Gao, Ning
    Liu, Yongchao
    Zhang, Ke
    PROCEEDINGS OF THE 29TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2023, 2023, : 3185 - 3194
  • [8] Generalizable Prompt Learning via Gradient Constrained Sharpness-Aware Minimization
    Liu, Liangchen
    Wang, Nannan
    Zhou, Dawei
    Liu, Decheng
    Yang, Xi
    Gao, Xinbo
    Liu, Tongliang
    IEEE TRANSACTIONS ON MULTIMEDIA, 2025, 27 : 1100 - 1113
  • [9] Binary Quantized Network Training With Sharpness-Aware Minimization
    Liu, Ren
    Bian, Fengmiao
    Zhang, Xiaoqun
    JOURNAL OF SCIENTIFIC COMPUTING, 2023, 94 (01)
  • [10] Binary Quantized Network Training With Sharpness-Aware Minimization
    Ren Liu
    Fengmiao Bian
    Xiaoqun Zhang
    Journal of Scientific Computing, 2023, 94