paper-with-me

홈 › Papers

Helper-based Adversarial Training: Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off

2021-06-18 · ICMLW 2021 6 · Rahul Rade, Seyed-Mohsen Moosavi-Dezfooli

While adversarial training has become the de facto approach for training robust classifiers, it leads to a drop in accuracy. This has led to prior works postulating that accuracy is inherently at odds with robustness. Yet, the phenomenon remains inexplicable. In this paper, we closely examine the changes induced in the decision boundary of a deep network during adversarial training. We find that adversarial training leads to unwarranted increase in the margin along certain adversarial directions, thereby hurting accuracy. Motivated by this observation, we present a novel algorithm, called Helper-based Adversarial Training (HAT), to reduce this effect by incorporating additional wrongly labelled examples during training. Our proposed method provides a notable improvement in accuracy without compromising robustness. It achieves a better trade-off between accuracy and robustness in comparison to existing defenses.

📄 PDF Abstract BibTeX

Code (2)

RobustBench/robustbench 공식 구현 pytorch
imrahulr/hat pytorch

Tasks

Adversarial DefenseAdversarial RobustnessRobust classification

Similar Papers 제목 키워드 기반

Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off

2021-09-29 · ICLR 2022 4 · Rahul Rade, Seyed-Mohsen Moosavi-Dezfooli

While adversarial training has become the de facto approach for training robust classifiers, it leads to a drop in accuracy. This has led to prior works postulating that accuracy is inherently at odds with robustness. Ye…

Self-Regulation and Requesting Interventions

2025-02-07 · So Yeon Min, Yue Wu, Jimin Sun, Max Kaufmann 외

Human intelligence involves metacognitive abilities like self-regulation, recognizing limitations, and seeking assistance only when needed. While LLM Agents excel in many domains, they often lack this awareness. Overconf…

Workflow Optimization for Parallel Split Learning

2024-02-01 · Joana Tirana, Dimitra Tsigkari, George Iosifidis, Dimitris Chatzopoulos

Split learning (SL) has been recently proposed as a way to enable resource-constrained devices to train multi-parameter neural networks (NNs) and participate in federated learning (FL). In a nutshell, SL splits the NN mo…

Federated LearningScheduling

FINED: Fast Inference Network for Edge Detection

2020-12-15 · Jan Kristanto Wibisono, Hsueh-Ming Hang

In this paper, we address the design of lightweight deep learning-based edge detection. The deep learning technology offers a significant improvement on the edge detection accuracy. However, typical neural network design…

Deep LearningEdge DetectionObject DetectionSemantic Segmentation

Increasing-Margin Adversarial (IMA) Training to Improve Adversarial Robustness of Neural Networks

2020-05-19 · Linhai Ma, Liang Liang

Deep neural networks (DNNs) are vulnerable to adversarial noises. By adding adversarial noises to training samples, adversarial training can improve the model's robustness against adversarial noises. However, adversarial…

Adversarial RobustnessGeneral ClassificationImage ClassificationImage Segmentation+3