paper-with-me

홈 › Papers

Adversarial Training Versus Weight Decay

2018-04-10 · Angus Galloway, Thomas Tanay, Graham W. Taylor

Performance-critical machine learning models should be robust to input perturbations not seen during training. Adversarial training is a method for improving a model's robustness to some perturbations by including them in the training process, but this tends to exacerbate other vulnerabilities of the model. The adversarial training framework has the effect of translating the data with respect to the cost function, while weight decay has a scaling effect. Although weight decay could be considered a crude regularization technique, it appears superior to adversarial training as it remains stable over a broader range of regimes and reduces all generalization errors. Equipped with these abstractions, we provide key baseline results and methodology for characterizing robustness. The two approaches can be combined to yield one small model that demonstrates good robustness to several white-box attacks associated with different metrics.

📄 PDF Abstract BibTeX arXiv:1804.03308

Code (2)

AngusG/tflite-android-black-box-attacks 공식 구현 tf
uoguelph-mlrg/adversarial_training_vs_weight_decay 공식 구현 tf

Methods 이 논문이 사용한 방법론

Weight Decay 설명 없음

Similar Papers 제목 키워드 기반

Critical Windows of Complexity Control: When Transformers Decide to Reason or Memorize

2026-05-06 · Sarwan Ali arxiv

Recent work has shown that Transformers' compositional generalization is governed by \emph{complexity control}, initialization scale and weight decay, which steers training toward low-complexity reasoning solutions rathe…

Improving Robustness with Adaptive Weight Decay

2022-09-30 · NeurIPS 2023 11 · Amin Ghiasi, Ali Shafahi, Reza Ardekani

We propose adaptive weight decay, which automatically tunes the hyper-parameter for weight decay during each training iteration. For classification problems, we propose changing the value of the weight decay hyper-parame…

Adversarial Robustness

Bag of Tricks for Adversarial Training

2020-10-01 · ICLR 2021 1 · Tianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su 외

Adversarial training (AT) is one of the most effective strategies for promoting model robustness. However, recent benchmarks show that most of the proposed improvements on AT are less effective than simply early stopping…

Adversarial RobustnessBenchmarking

L2 Regularization versus Batch and Weight Normalization

2017-06-16 · Twan van Laarhoven

Batch Normalization is a commonly used trick to improve the training of deep neural networks. These neural networks use L2 regularization, also called weight decay, ostensibly to prevent overfitting. However, we show tha…

L2 Regularization

Large Norms of CNN Layers Do Not Hurt Adversarial Robustness

2020-09-17 · Youwei Liang, Dong Huang

Since the Lipschitz properties of convolutional neural networks (CNNs) are widely considered to be related to adversarial robustness, we theoretically characterize the $\ell_1$ norm and $\ell_\infty$ norm of 2D multi-cha…

Adversarial Robustness