What Do Adversarially trained Neural Networks Focus: A Fourier Domain-based Study
Although many fields have witnessed the superior performance brought about by deep learning, the robustness of neural networks remains an open issue. Specifically, a small adversarial perturbation on the input may cause the model to produce a completely different output. Such poor robustness implies many potential hazards, especially in security-critical applications, e.g., autonomous driving and mobile robotics. This work studies what information the adversarially trained model focuses on. Empirically, we notice that the differences between the clean and adversarial data are mainly distributed in the low-frequency region. We then find that an adversarially-trained model is more robust than its naturally-trained counterpart due to the reason that the former pays more attention to learning the dominant information in low-frequency components. In addition, we consider two common ways to improve model robustness, namely, by data augmentation and by using stronger network architectures, and understand these techniques from a frequency-domain perspective. We are hopeful this work can shed light on the design of more robust neural networks.
Code (0)
등록된 구현이 없습니다.
Tasks
Autonomous DrivingData AugmentationSimilar Papers 제목 키워드 기반
Adversarially Trained Neural Policies in the Fourier Domain
Reinforcement learning policies based on deep neural networks are vulnerable to imperceptible adversarial perturbations to their inputs, in much the same way as neural network image classifiers. Recent work has proposed …
Deep Reinforcement Learningreinforcement-learningReinforcement LearningReinforcement Learning (RL)Investigating Vulnerabilities of Deep Neural Policies
Reinforcement learning policies based on deep neural networks are vulnerable to imperceptible adversarial perturbations to their inputs, in much the same way as neural network image classifiers. Recent work has proposed …
Deep Reinforcement Learningreinforcement-learningReinforcement Learning (RL)SensitivityDeepDGA: Adversarially-Tuned Domain Generation and Detection
Many malware families utilize domain generation algorithms (DGAs) to establish command and control (C&C) connections. While there are many methods to pseudorandomly generate domains, we focus in this paper on detecting (…
BIG-bench Machine LearningDecoderDeep LearningGenerative Adversarial NetworkDomain Generalisation via Domain Adaptation: An Adversarial Fourier Amplitude Approach
We tackle the domain generalisation (DG) problem by posing it as a domain adaptation (DA) task where we adversarially synthesise the worst-case target domain and adapt a model to that worst-case domain, thereby improving…
Domain AdaptationWhat Do Adversarially Robust Models Look At?
In this paper, we address the open question: "What do adversarially robust models look at?" Recently, it has been reported in many works that there exists the trade-off between standard accuracy and adversarial robustnes…
Adversarial RobustnessOpen-Ended Question Answering