paper-with-me

홈 › Papers

Adversarial Training Can Hurt Generalization

2019-06-14 · ICML Workshop Deep_Phenomen 2019 6 · Aditi Raghunathan, Sang Michael Xie, Fanny Yang, John C. Duchi, Percy Liang

While adversarial training can improve robust accuracy (against an adversary), it sometimes hurts standard accuracy (when there is no adversary). Previous work has studied this tradeoff between standard and robust accuracy, but only in the setting where no predictor performs well on both objectives in the infinite data limit. In this paper, we show that even when the optimal predictor with infinite data performs well on both objectives, a tradeoff can still manifest itself with finite data. Furthermore, since our construction is based on a convex learning problem, we rule out optimization concerns, thus laying bare a fundamental tension between robustness and generalization. Finally, we show that robust self-training mostly eliminates this tradeoff by leveraging unlabeled data.

📄 PDF Abstract BibTeX arXiv:1906.06032

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

The Curious Case of Adversarially Robust Models: More Data Can Help, Double Descend, or Hurt Generalization

2020-02-25 · Yifei Min, Lin Chen, Amin Karbasi

Adversarial training has shown its ability in producing models that are robust to perturbations on the input data, but usually at the expense of decrease in the standard accuracy. To mitigate this issue, it is commonly b…

ClassificationGeneral Classification

Why adversarial training can hurt robust accuracy

2022-03-03 · Jacob Clarysse, Julia Hörmann, Fanny Yang

Machine learning classifiers with high test accuracy often perform poorly under adversarial attacks. It is commonly believed that adversarial training alleviates this issue. In this paper, we demonstrate that, surprising…

Attacks Which Do Not Kill Training Make Adversarial Learning Stronger

2020-02-26 · ICML 2020 1 · Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu 외

Adversarial training based on the minimax formulation is necessary for obtaining adversarial robustness of trained models. However, it is conservative or even pessimistic so that it sometimes hurts the natural generaliza…

Adversarial Robustness

Adversarial Training for Large Neural Language Models

2020-04-20 · Xiaodong Liu, Hao Cheng, Pengcheng He, Weizhu Chen 외

Generalization and robustness are both key desiderata for designing machine learning methods. Adversarial training can enhance robustness, but past work often finds it hurts generalization. In natural language processing…

Natural Language InferenceNatural Language Understanding

Interpolated Adversarial Training: Achieving Robust Neural Networks without Sacrificing Too Much Accuracy

2019-06-16 · Alex Lamb, Vikas Verma, Kenji Kawaguchi, Alexander Matyasko 외

Adversarial robustness has become a central goal in deep learning, both in the theory and the practice. However, successful methods to improve the adversarial robustness (such as adversarial training) greatly hurt genera…

Adversarial Robustness