Improving Adversarial Robustness via Unlabeled Out-of-Domain Data

被引:0
|
作者
Deng, Zhun [1 ]
Zhang, Linjun [2 ]
Ghorbani, Amirata [3 ]
Zou, James [3 ]
机构
[1] Harvard Univ, Cambridge, MA 02138 USA
[2] Rutgers State Univ, New Brunswick, NJ USA
[3] Stanford Univ, Stanford, CA 94305 USA
来源
24TH INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND STATISTICS (AISTATS) | 2021年 / 130卷
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Data augmentation by incorporating cheap unlabeled data from multiple domains is a powerful way to improve prediction especially when there is limited labeled data. In this work, we investigate how adversarial robustness can be enhanced by leveraging out-of-domain unlabeled data. We demonstrate that for broad classes of distributions and classifiers, there exists a sample complexity gap between standard and robust classification. We quantify the extent to which this gap can be bridged by leveraging unlabeled samples from a shifted domain by providing both upper and lower bounds. Moreover, we show settings where we achieve better adversarial robustness when the unlabeled data come from a shifted domain rather than the same domain as the labeled data. We also investigate how to leverage out-of-domain data when some structural information, such as sparsity, is shared between labeled and unlabeled domains. Experimentally, we augment object recognition datasets (CIFAR10, CINIC-10, and SVHN) with easy-to-obtain and unlabeled out-of-domain data and demonstrate substantial improvement in the model's robustness against `1 adversarial attacks on the original domain.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] Improving Adversarial Robustness of Detector via Objectness Regularization
    Bao, Jiayu
    Chen, Jiansheng
    Ma, Hongbing
    Ma, Huimin
    Yu, Cheng
    Huang, Yiqing
    PATTERN RECOGNITION AND COMPUTER VISION, PT IV, 2021, 13022 : 252 - 262
  • [32] Improving Adversarial Robustness via Information Bottleneck Distillation
    Kuang, Huafeng
    Liu, Hong
    Wu, YongJian
    Satoh, Shin'ichi
    Ji, Rongrong
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [33] Improving Adversarial Robustness via Promoting Ensemble Diversity
    Pang, Tianyu
    Xu, Kun
    Du, Chao
    Chen, Ning
    Zhu, Jun
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 97, 2019, 97
  • [34] Improving Adversarial Robustness of CNNs via Maximum Margin
    Wu, Jiaping
    Xia, Zhaoqiang
    Feng, Xiaoyi
    APPLIED SCIENCES-BASEL, 2022, 12 (15):
  • [35] Improving Adversarial Robustness via Mutual Information Estimation
    Zhou, Dawei
    Wang, Nannan
    Gao, Xinbo
    Han, Bo
    Wang, Xiaoyu
    Zhan, Yibing
    Liu, Tongliang
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [36] Class-aware domain adaptation for improving adversarial robustness
    Hou, Xianxu
    Liu, Jingxin
    Xu, Bolei
    Wang, Xiaolong
    Liu, Bozhi
    Qiu, Guoping
    IMAGE AND VISION COMPUTING, 2020, 99 (99)
  • [37] Improving Adversarial Robustness With Adversarial Augmentations
    Chen, Chuanxi
    Ye, Dengpan
    He, Yiheng
    Tang, Long
    Xu, Yue
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (03) : 5105 - 5117
  • [38] FFM: Injecting Out-of-Domain Knowledge via Factorized Frequency Modification
    Wang, Zijian
    Luo, Yadan
    Huang, Zi
    Baktashmotlagh, Mahsa
    2023 IEEE/CVF WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV), 2023, : 4124 - 4133
  • [39] Improving Robustness of Speaker Recognition to New Conditions Using Unlabeled Data
    Castan, Diego
    McLaren, Mitchell
    Ferrer, Luciana
    Lawson, Aaron
    Lozano-Diez, Alicia
    18TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION (INTERSPEECH 2017), VOLS 1-6: SITUATED INTERACTION, 2017, : 3737 - 3741
  • [40] Improving child speech disorder assessment by incorporating out-of-domain adult speech
    Smith, Daniel
    Sneddon, Alex
    Ward, Lauren
    Duenser, Andreas
    Freyne, Jill
    Silvera-Tawil, David
    Morgans, Angela
    18TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION (INTERSPEECH 2017), VOLS 1-6: SITUATED INTERACTION, 2017, : 2690 - 2694