paper-with-me

Papers

Adversarially Robust Generalization Just Requires More Unlabeled Data

2019-06-03 · Runtian Zhai, Tianle Cai, Di He, Chen Dan, Kun He, John Hopcroft, Li-Wei Wang

Neural network robustness has recently been highlighted by the existence of adversarial examples. Many previous works show that the learned networks do not perform well on perturbed test data, and significantly more labeled data is required to achieve adversarially robust generalization. In this paper, we theoretically and empirically show that with just more unlabeled data, we can learn a model with better adversarially robust generalization. The key insight of our results is based on a risk decomposition theorem, in which the expected robust risk is separated into two parts: the stability part which measures the prediction stability in the presence of perturbations, and the accuracy part which evaluates the standard classification accuracy. As the stability part does not depend on any label information, we can optimize this part using unlabeled data. We further prove that for a specific Gaussian mixture problem, adversarially robust generalization can be almost as easy as the standard generalization in supervised learning if a sufficiently large amount of unlabeled data is provided. Inspired by the theoretical findings, we further show that a practical adversarial training algorithm that leverages unlabeled data can improve adversarial robust generalization on MNIST and Cifar-10.

📄 PDF Abstract BibTeX arXiv:1906.00555

Code (1)

RuntianZ/adversarial-robustness-unlabeled pytorch

Similar Papers 제목 키워드 기반

ARMOURED: Adversarially Robust MOdels using Unlabeled data by REgularizing Diversity

2021-01-01 · ICLR 2021 1 · Kangkang Lu, Cuong Manh Nguyen, Xun Xu, Kiran Chari 외

Adversarial attacks pose a major challenge for modern deep neural networks. Recent advancements show that adversarially robust generalization requires a huge amount of labeled data for training. If annotation becomes a b…

DiversityMULTI-VIEW LEARNINGPoint Processes

Adversarially Robust Estimate and Risk Analysis in Linear Regression

2020-12-18 · Yue Xing, Ruizhi Zhang, Guang Cheng

Adversarially robust learning aims to design algorithms that are robust to small adversarial perturbations on input variables. Beyond the existing studies on the predictive performance to adversarial samples, our goal is…

Adversarial Robustnessregression

Are Labels Required for Improving Adversarial Robustness?

2019-05-31 · NeurIPS 2019 12 · Jonathan Uesato, Jean-Baptiste Alayrac, Po-Sen Huang, Robert Stanforth 외

Recent work has uncovered the interesting (and somewhat surprising) finding that training models to be invariant to adversarial perturbations requires substantially larger datasets than those required for standard classi…

4kAdversarial Robustness

Exploring Adversarially Robust Training for Unsupervised Domain Adaptation

2022-02-18 · Shao-Yuan Lo, Vishal M. Patel

Unsupervised Domain Adaptation (UDA) methods aim to transfer knowledge from a labeled source domain to an unlabeled target domain. UDA has been extensively studied in the computer vision literature. Deep networks have be…

Adversarial DefenseAdversarial RobustnessDomain AdaptationUnsupervised Domain Adaptation

Self-supervised Adversarial Robustness for the Low-label, High-data Regime

2021-01-01 · ICLR 2021 1 · Sven Gowal, Po-Sen Huang, Aaron van den Oord, Timothy Mann 외

Recent work discovered that training models to be invariant to adversarial perturbations requires substantially larger datasets than those required for standard classification. Perhaps more surprisingly, these larger dat…

Adversarial RobustnessSelf-Supervised LearningVocal Bursts Intensity Prediction