Adversarial Training is a Form of Data-dependent Operator Norm Regularization
We establish a theoretical link between adversarial training and operator norm regularization for deep neural networks. Specifically, we prove that $\ell_p$-norm constrained projected gradient ascent based adversarial training with an $\ell_q$-norm loss on the logits of clean and perturbed inputs is equivalent to data-dependent (p, q) operator norm regularization. This fundamental connection confirms the long-standing argument that a network's sensitivity to adversarial examples is tied to its spectral properties and hints at novel ways to robustify and defend against adversarial attacks. We provide extensive empirical evidence on state-of-the-art network architectures to support our theoretical results.
Code (0)
등록된 구현이 없습니다.
Tasks
FormSensitivitySimilar Papers 제목 키워드 기반
Adversarial Training Generalizes Data-dependent Spectral Norm Regularization
We establish a theoretical link between adversarial training and operator norm regularization for deep neural networks. Specifically, we present a data-dependent variant of spectral norm regularization and prove that it …
SensitivityData-Independent Operator: A Training-Free Artifact Representation Extractor for Generalizable Deepfake Detection
Recently, the proliferation of increasingly realistic synthetic images generated by various generative adversarial networks has increased the risk of misuse. Consequently, there is a pressing need to develop a generaliza…
DeepFake DetectionFace SwappingSolver-Integrated Adversarial Attacking and Training of Neural Operators
Neural operators are widely used as fast surrogates for numerical PDE solvers, mapping input functions to solution functions. However, their generalizability and robustness are not yet clearly defined in the operator-lea…
Adversarial RobustnessAdversarial AttackBeyond Uniform Sampling: Synergistic Active Learning and Input Denoising for Robust Neural Operators
Neural operators have emerged as fast surrogate models for physics simulations, yet they remain acutely vulnerable to adversarial perturbations, a critical liability for safety-critical digital twin deployments. We prese…
Active LearningThe Geometry of Adversarial Training in Binary Classification
We establish an equivalence between a family of adversarial training problems for non-parametric binary classification and a family of regularized risk minimization problems where the regularizer is a nonlocal perimeter …
Binary ClassificationClassification