Unifying Adversarial Training Algorithms with Data Gradient Regularization

被引:11
|
作者
Ororbia, Alexander G., II [1 ]
Kifer, Daniel [1 ]
Giles, C. Lee [1 ]
机构
[1] Penn State Univ, University Pk, PA 16802 USA
关键词
D O I
10.1162/NECO_a_00928
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Many previous proposals for adversarial training of deep neural nets have included directly modifying the gradient, training on a mix of original and adversarial examples, using contractive penalties, and approximately optimizing constrained adversarial objective functions. In this article, we show that these proposals are actually all instances of optimizing a general, regularized objective we call DataGrad. Our proposed DataGrad framework, which can be viewed as a deep extension of the layerwise contractive autoencoder penalty, cleanly simplifies prior work and easily allows extensions such as adversarial training with multitask cues. In our experiments, we find that the deep gradient regularization of DataGrad (which also has L1 and L2 flavors of regularization) outperforms alternative forms of regularization, including classical L1, L2, and multitask, on both the original data set and adversarial sets. Furthermore, we find that combining multitask optimization with DataGrad adversarial training results in the most robust performance.
引用
收藏
页码:867 / 887
页数:21
相关论文
共 50 条
  • [1] Adversarial Training with Orthogonal Regularization
    Yuksel, Oguz Kaan
    Baytas, Inci Meliha
    2020 28TH SIGNAL PROCESSING AND COMMUNICATIONS APPLICATIONS CONFERENCE (SIU), 2020,
  • [2] Adversarial Training is a Form of Data-dependent Operator Norm Regularization
    Roth, Kevin
    Kilcher, Yannic
    Hofmann, Thomas
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS (NEURIPS 2020), 2020, 33
  • [3] Wavelet regularization benefits adversarial training
    Yan, Jun
    Yin, Huilin
    Zhao, Ziming
    Ge, Wancheng
    Zhang, Hao
    Rigoll, Gerhard
    INFORMATION SCIENCES, 2023, 649
  • [4] ADVERSARIAL TRAINING WITH CHANNEL ATTENTION REGULARIZATION
    Cho, Seungju
    Byun, Junyoung
    Kwon, Myung-Joon
    Kim, Yoonji
    Kim, Changick
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 2996 - 3000
  • [5] Scaleable input gradient regularization for adversarial robustness
    Finlay, Chris
    Oberman, Adam M.
    MACHINE LEARNING WITH APPLICATIONS, 2021, 3
  • [6] A Unified Gradient Regularization Family for Adversarial Examples
    Lyu, Chunchuan
    Huang, Kaizhu
    Liang, Hai-Ning
    2015 IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2015, : 301 - 309
  • [7] DigGAN: Discriminator gradIent Gap Regularization for GAN Training with Limited Data
    Fang, Tiantian
    Sun, Ruoyu
    Schwing, Alex
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35 (NEURIPS 2022), 2022,
  • [8] Comparative Study of Adversarial Defenses: Adversarial Training and Regularization in Vision Transformers and CNNs
    Dingeto, Hiskias
    Kim, Juntae
    ELECTRONICS, 2024, 13 (13)
  • [9] Stabilizing Training of Generative Adversarial Networks through Regularization
    Roth, Kevin
    Lucchi, Aurelien
    Nowozin, Sebastian
    Hofmann, Thomas
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 30 (NIPS 2017), 2017, 30
  • [10] Transferable Adversarial Attacks on Vision Transformers with Token Gradient Regularization
    Zhang, Jianping
    Huang, Yizhan
    Wu, Weibin
    Lyu, Michael R.
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 16415 - 16424