Delving Deeper Into Vulnerable Samples in Adversarial Training

Pengfei Zhao,Haojie Yuan,Qi Chu, Shubin Xu,Nenghai Yu

ICASSP 2024 - 2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)(2024)

Cited 0|Views9
No score
Abstract
Recently, vulnerable samples have been shown to be crucial for improving adversarial training performance. Our analysis on existing vulnerable samples mining methods indicate that existing methods have two problems: 1) valuable connections among different pairs of natural samples and their adversarial counterparts are ignored; 2) parts of vulnerable samples are unconsidered. To better leverage vulnerable samples, we propose INter PAir ConstrainT (INPACT) and Vulnerable Aware adveRsarial Training (VART) to address these drawbacks respectively. INPACT assesses adversarial risk with more comprehensive regularization on sample relationships, which takes both inter and intra connections of natural/adversarial sample pairs into consideration. Meanwhile VART makes full use of all vulnerable samples, including notable proportion neglected by existing instance re-weighting strategies. Extensive experiments on different datasets and backbones demonstrate the effectiveness of the proposed method.
More
Translated text
Key words
Adversarial training,Vulunerable samples
AI Read Science
Must-Reading Tree
Example
Generate MRT to find the research sequence of this paper
Chat Paper
Summary is being generated by the instructions you defined