paper-with-me

Papers

Stable and Efficient Adversarial Training through Local Linearization

2022-10-11 · Zhuorong Li, Daiwei Yu

There has been a recent surge in single-step adversarial training as it shows robustness and efficiency. However, a phenomenon referred to as ``catastrophic overfitting" has been observed, which is prevalent in single-step defenses and may frustrate attempts to use FGSM adversarial training. To address this issue, we propose a novel method, Stable and Efficient Adversarial Training (SEAT), which mitigates catastrophic overfitting by harnessing on local properties that distinguish a robust model from that of a catastrophic overfitted model. The proposed SEAT has strong theoretical justifications, in that minimizing the SEAT loss can be shown to favour smooth empirical risk, thereby leading to robustness. Experimental results demonstrate that the proposed method successfully mitigates catastrophic overfitting, yielding superior performance amongst efficient defenses. Our single-step method can reach 51% robust accuracy for CIFAR-10 with $l_\infty$ perturbations of radius $8/255$ under a strong PGD-50 attack, matching the performance of a 10-step iterative adversarial training at merely 3% computational cost.

📄 PDF Abstract BibTeX arXiv:2210.05373

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Learned Lifted Linearization Applied to Unstable Dynamic Systems Enabled by Koopman Direct Encoding

2022-10-24 · Jerry Ng, H. Harry Asada

This paper presents a Koopman lifting linearization method that is applicable to nonlinear dynamical systems having both stable and unstable regions. It is known that DMD and other standard data-driven methods face a fun…

On the Implicit Flatness Bias of Sharpness-Aware Minimization: A Linear Stability Analysis with Quantitative Hyperparameter Bounds

2026-08-04 · Jiaxin Deng, Junbiao Pang arxiv

Sharpness-Aware Minimization (SAM) improves generalization by seeking parameters whose loss is robust to local adversarial perturbations, but the quantitative mechanism underlying its implicit bias toward flat minima rem…

Uncertainty Quantification via Stable Distribution Propagation

2024-02-13 · Felix Petersen, Aashwin Mishra, Hilde Kuehne, Christian Borgelt 외

We propose a new approach for propagating stable probability distributions through neural networks. Our method is based on local linearization, which we show to be an optimal approximation in terms of total variation dis…

Uncertainty Quantification

Adversarial Robustness through Local Linearization

2019-07-04 · NeurIPS 2019 12 · Chongli Qin, James Martens, Sven Gowal, Dilip Krishnan 외

Adversarial training is an effective methodology for training deep neural networks that are robust against adversarial, norm-bounded perturbations. However, the computational cost of adversarial training grows prohibitiv…

Adversarial DefenseAdversarial Robustness

Propagating Distributions through Neural Networks

2021-09-29 · Felix Petersen, Christian Borgelt, Mikhail Yurochkin, Hilde Kuehne 외

We propose a new approach to propagating probability distributions through neural networks. To handle non-linearities, we use local linearization and show this to be an optimal approximation in terms of total variation f…

Predictionregression