Current browse context:
stat.ML
Change to browse by:
References & Citations
Statistics > Machine Learning
Title: Towards Evaluating and Understanding Robust Optimisation under Transfer
(Submitted on 7 May 2019 (this version), latest version 8 Jun 2019 (v4))
Abstract: This work evaluates the efficacy of adversarial robustness under transfer from CIFAR 100 to CIFAR 10. This allows us to identify transfer learning strategies under which adversarial defences are successfully retained, in addition to revealing potential vulnerabilities. We study the extent to which features crafted by fast gradient sign methods (FGSM) and their iterative alternative (PGD) can preserve their defence properties against black and white-box attacks under three different transfer learning strategies. We find that using PGD examples during training leads to more general robustness that is easier to transfer. Furthermore, under successful transfer, it achieves 5.2% more accuracy against white-box PGD attacks than the considered baselines. In this paper, we study the effects of using robust optimisation in the source and target networks. Our empirical evaluation sheds light on how well such mechanisms generalise while achieving comparable results to non-transferred defences.
Submission history
From: Todor Davchev [view email][v1] Tue, 7 May 2019 16:26:26 GMT (483kb,D)
[v2] Thu, 9 May 2019 00:34:28 GMT (483kb,D)
[v3] Thu, 23 May 2019 09:37:44 GMT (483kb,D)
[v4] Sat, 8 Jun 2019 22:25:52 GMT (650kb,D)
Link back to: arXiv, form interface, contact.