Efficient Adversarial Training with Transferable Adversarial Examples

被引:78
作者
Zheng, Haizhong [1 ]
Zhang, Ziqi [1 ]
Gu, Juncheng [1 ]
Lee, Honglak [1 ]
Prakash, Atul [1 ]
机构
[1] Univ Michigan, Ann Arbor, MI 48109 USA
来源
2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR) | 2020年
基金
美国国家科学基金会;
关键词
D O I
10.1109/CVPR42600.2020.00126
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Adversarial training is an effective defense method to protect classification models against adversarial attacks. However, one limitation of this approach is that it can require orders of magnitude additional training time due to high cost of generating strong adversarial examples during training. In this paper, we first show that there is high transferability between models from neighboring epochs in the same training process, i.e., adversarial examples from one epoch continue to be adversarial in subsequent epochs. Leveraging this property, we propose a novel method, Adversarial Training with Transferable Adversarial Examples (ATTA), that can enhance the robustness of trained models and greatly improve the training efficiency by accumulating adversarial perturbations through epochs. Compared to state-of-the-art adversarial training methods, AIM enhances adversarial accuracy by up to 7.2% on CIFAR10 and requires 12 similar to 14x less training time on MNIST and CIFAR10 datasets with comparable model robustness.
引用
收藏
页码:1178 / 1187
页数:10
相关论文
共 34 条
[11]  
Deng J, 2009, PROC CVPR IEEE, P248, DOI 10.1109/CVPRW.2009.5206848
[12]  
Eykholt Kevin, 2019, P IEEE C COMP VIS PA
[13]  
Hein M, 2017, ADV NEUR IN, V30
[14]  
Hendrycks D, 2019, PR MACH LEARN RES, V97
[15]   Adversarial Defense via Learning to Generate Diverse Attacks [J].
Jang, Yunseok ;
Zhao, Tianchen ;
Hong, Seunghoon ;
Lee, Honglak .
2019 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2019), 2019, :2740-2749
[16]  
Krizhevsky A, 2009, LEARNING MULTIPLE LA
[17]   Gradient-based learning applied to document recognition [J].
Lecun, Y ;
Bottou, L ;
Bengio, Y ;
Haffner, P .
PROCEEDINGS OF THE IEEE, 1998, 86 (11) :2278-2324
[18]  
Lee H., 2017, GENERATIVE ADVERSARI
[19]  
Li YH, 2020, AAAI CONF ARTIF INTE, V34, P4780
[20]  
Liu Y, 2016, ADVANCES OF ATOMS AND MOLECULES IN STRONG LASER FIELDS, P1