We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CV

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Computer Vision and Pattern Recognition

Title: Boosting Fast Adversarial Training with Learnable Adversarial Initialization

Abstract: Adversarial training (AT) has been demonstrated to be effective in improving model robustness by leveraging adversarial examples for training. However, most AT methods are in face of expensive time and computational cost for calculating gradients at multiple steps in generating adversarial examples. To boost training efficiency, fast gradient sign method (FGSM) is adopted in fast AT methods by calculating gradient only once. Unfortunately, the robustness is far from satisfactory. One reason may arise from the initialization fashion. Existing fast AT generally uses a random sample-agnostic initialization, which facilitates the efficiency yet hinders a further robustness improvement. Up to now, the initialization in fast AT is still not extensively explored. In this paper, we boost fast AT with a sample-dependent adversarial initialization, i.e., an output from a generative network conditioned on a benign image and its gradient information from the target network. As the generative network and the target network are optimized jointly in the training phase, the former can adaptively generate an effective initialization with respect to the latter, which motivates gradually improved robustness. Experimental evaluations on four benchmark databases demonstrate the superiority of our proposed method over state-of-the-art fast AT methods, as well as comparable robustness to advanced multi-step AT methods. The code is released at this https URL
Comments: Accepted by TIP
Subjects: Computer Vision and Pattern Recognition (cs.CV); Machine Learning (cs.LG)
DOI: 10.1109/TIP.2022.3184255
Cite as: arXiv:2110.05007 [cs.CV]
  (or arXiv:2110.05007v3 [cs.CV] for this version)

Submission history

From: Xiaojun Jia [view email]
[v1] Mon, 11 Oct 2021 05:37:00 GMT (1727kb,D)
[v2] Thu, 9 Jun 2022 12:04:22 GMT (2070kb,D)
[v3] Fri, 17 Jun 2022 11:17:52 GMT (2072kb,D)

Link back to: arXiv, form interface, contact.