Adversarial Training for Improving the Robustness of Deep Neural Networks

Adversarial Training for Improving the Robustness of Deep Neural Networks
Author :
Publisher :
Total Pages : 0
Release :
ISBN-10 : OCLC:1415634068
ISBN-13 :
Rating : 4/5 (68 Downloads)

Book Synopsis Adversarial Training for Improving the Robustness of Deep Neural Networks by : Pengyue Hou

Download or read book Adversarial Training for Improving the Robustness of Deep Neural Networks written by Pengyue Hou and published by . This book was released on 2022 with total page 0 pages. Available in PDF, EPUB and Kindle. Book excerpt: Since 2013, Deep Neural Networks (DNNs) have caught up to a human-level performance at various benchmarks. Meanwhile, it is essential to ensure its safety and reliability. Recently an avenue of study questions the robustness of deep learning models and shows that adversarial samples with human-imperceptible noise can easily fool DNNs. Since then, many strategies have been proposed to improve the robustness of DNNs against such adversarial perturbations. Among many defense strategies, adversarial training (AT) is one of the most recognized methods and constantly yields state-of-the-art performance. It treats adversarial samples as augmented data and uses them in model optimization. Despite its promising results, AT has two problems to be improved: (1) poor generalizability on adversarial data (e.g. large robustness performance gap between training and testing data), and (2) a big drop in model's standard performance. This thesis tackles the above-mentioned drawbacks in AT and introduces two AT strategies. To improve the generalizability of AT-trained models, the first part of the thesis introduces a representation similarity-based AT strategy, namely self-paced adversarial training (SPAT). We investigate the imbalanced semantic similarity among different categories in natural images and discover that DNN models are easily fooled by adversarial samples from their hard-class pairs. With this insight, we propose SPAT to re-weight training samples adaptively during model optimization, enforcing AT to focus on those data from their hard class pairs. To address the second problem in AT, a big performance drop on clean data, the second part of this thesis attempts to answer the question: to what extent the robustness of the model can be improved without sacrificing standard performance? Toward this goal, we propose a simple yet effective transfer learning-based adversarial training strategy that disentangles the negative effects of adversarial samples on model's standard performance. In addition, we introduce a training-friendly adversarial attack algorithm, which boosts adversarial robustness without introducing significant training complexity. Compared to prior arts, extensive experiments demonstrate that the training strategy leads to a more robust model while preserving the model's standard accuracy on clean data.


Adversarial Training for Improving the Robustness of Deep Neural Networks Related Books

Adversarial Training for Improving the Robustness of Deep Neural Networks
Language: en
Pages: 0
Authors: Pengyue Hou
Categories: Computer vision
Type: BOOK - Published: 2022 - Publisher:

DOWNLOAD EBOOK

Since 2013, Deep Neural Networks (DNNs) have caught up to a human-level performance at various benchmarks. Meanwhile, it is essential to ensure its safety and r
Adversarial Robustness of Deep Learning Models
Language: en
Pages: 80
Authors: Samarth Gupta (S.M.)
Categories:
Type: BOOK - Published: 2020 - Publisher:

DOWNLOAD EBOOK

Efficient operation and control of modern day urban systems such as transportation networks is now more important than ever due to huge societal benefits. Low c
On the Robustness of Neural Network: Attacks and Defenses
Language: en
Pages: 158
Authors: Minhao Cheng
Categories:
Type: BOOK - Published: 2021 - Publisher:

DOWNLOAD EBOOK

Neural networks provide state-of-the-art results for most machine learning tasks. Unfortunately, neural networks are vulnerable to adversarial examples. That is
Strengthening Deep Neural Networks
Language: en
Pages: 246
Authors: Katy Warr
Categories: Computers
Type: BOOK - Published: 2019-07-03 - Publisher: "O'Reilly Media, Inc."

DOWNLOAD EBOOK

As deep neural networks (DNNs) become increasingly common in real-world applications, the potential to deliberately "fool" them with data that wouldn’t trick
Security, Privacy, and Anonymity in Computation, Communication, and Storage
Language: en
Pages: 436
Authors: Guojun Wang
Categories: Computers
Type: BOOK - Published: 2021-02-04 - Publisher: Springer Nature

DOWNLOAD EBOOK

This book constitutes the refereed proceedings of the 13th International Conference on Security, Privacy, and Anonymity in Computation, Communication, and Stora