Delving Deeper Into Vulnerable Samples in Adversarial Training
ICASSP 2024 - 2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)(2024)
Abstract
Recently, vulnerable samples have been shown to be crucial for improving adversarial training performance. Our analysis on existing vulnerable samples mining methods indicate that existing methods have two problems: 1) valuable connections among different pairs of natural samples and their adversarial counterparts are ignored; 2) parts of vulnerable samples are unconsidered. To better leverage vulnerable samples, we propose INter PAir ConstrainT (INPACT) and Vulnerable Aware adveRsarial Training (VART) to address these drawbacks respectively. INPACT assesses adversarial risk with more comprehensive regularization on sample relationships, which takes both inter and intra connections of natural/adversarial sample pairs into consideration. Meanwhile VART makes full use of all vulnerable samples, including notable proportion neglected by existing instance re-weighting strategies. Extensive experiments on different datasets and backbones demonstrate the effectiveness of the proposed method.
MoreTranslated text
Key words
Adversarial training,Vulunerable samples
AI Read Science
Must-Reading Tree
Example
![](https://originalfileserver.aminer.cn/sys/aminer/pubs/mrt_preview.jpeg)
Generate MRT to find the research sequence of this paper
Chat Paper
Summary is being generated by the instructions you defined