paper-with-me

홈 › Papers

Why adversarial training can hurt robust accuracy

2022-03-03 · Jacob Clarysse, Julia Hörmann, Fanny Yang

Machine learning classifiers with high test accuracy often perform poorly under adversarial attacks. It is commonly believed that adversarial training alleviates this issue. In this paper, we demonstrate that, surprisingly, the opposite may be true -- Even though adversarial training helps when enough data is available, it may hurt robust generalization in the small sample size regime. We first prove this phenomenon for a high-dimensional linear classification setting with noiseless observations. Our proof provides explanatory insights that may also transfer to feature learning models. Further, we observe in experiments on standard image datasets that the same behavior occurs for perceptible attacks that effectively reduce class information such as mask attacks and object corruptions.

📄 PDF Abstract BibTeX arXiv:2203.02006

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

The Curious Case of Adversarially Robust Models: More Data Can Help, Double Descend, or Hurt Generalization

2020-02-25 · Yifei Min, Lin Chen, Amin Karbasi

Adversarial training has shown its ability in producing models that are robust to perturbations on the input data, but usually at the expense of decrease in the standard accuracy. To mitigate this issue, it is commonly b…

ClassificationGeneral Classification

Adversarial Training Can Hurt Generalization

2019-06-14 · ICML Workshop Deep_Phenomen 2019 6 · Aditi Raghunathan, Sang Michael Xie, Fanny Yang, John C. Duchi 외

While adversarial training can improve robust accuracy (against an adversary), it sometimes hurts standard accuracy (when there is no adversary). Previous work has studied this tradeoff between standard and robust accura…

Helper-based Adversarial Training: Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off

2021-06-18 · ICMLW 2021 6 · Rahul Rade, Seyed-Mohsen Moosavi-Dezfooli

While adversarial training has become the de facto approach for training robust classifiers, it leads to a drop in accuracy. This has led to prior works postulating that accuracy is inherently at odds with robustness. Ye…

Adversarial DefenseAdversarial RobustnessRobust classification

Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off

2021-09-29 · ICLR 2022 4 · Rahul Rade, Seyed-Mohsen Moosavi-Dezfooli

While adversarial training has become the de facto approach for training robust classifiers, it leads to a drop in accuracy. This has led to prior works postulating that accuracy is inherently at odds with robustness. Ye…

PUMA: margin-based data pruning

2024-05-10 · Javier Maroto, Pascal Frossard

Deep learning has been able to outperform humans in terms of classification accuracy in many tasks. However, to achieve robustness to adversarial perturbations, the best methodologies require to perform adversarial train…