清晨好,您是今天最早来到科研通的研友!由于当前在线用户较少,发布求助请尽量完整地填写文献信息,科研通机器人24小时在线,伴您科研之路漫漫前行!

Analyzing the Implicit Bias of Adversarial Training From a Generalized Margin Perspective

对抗制 透视图(图形) 边距(机器学习) 人工智能 计算机科学 培训(气象学) 机器学习 模式识别(心理学) 算法 物理 气象学
作者
Bochen Lyu,Zhanxing Zhu
出处
期刊:IEEE Transactions on Pattern Analysis and Machine Intelligence [IEEE Computer Society]
卷期号:47 (9): 8025-8039
标识
DOI:10.1109/tpami.2025.3575618
摘要

Adversarial training has been empirically demonstrated as an effective strategy to improve the robustness of deep neural networks (DNNs) against adversarial examples. However, the underlying reason of its effectiveness is still non-transparent. In this paper we conduct both extensive theoretical and empirical analysis on the implicit bias induced by adversarial training from a generalized margin perspective. Our results focus on adversarial training for homogeneous DNNs. In particular, (i) For deep linear networks with $\ell _{p}$ℓp-norm perturbation, we show that weight matrices of adjacent layers get aligned and the converged parameters maximize the margin of adversarial examples, which can be further viewed as a generalized margin of the original dataset that can be achieved by an interpolation solution between $\ell _{2}$ℓ2-SVM and $\ell _{q}$ℓq-SVM where $1/p + 1/q=1$1/p+1/q=1. (ii) For general homogeneous DNNs, including both linear and nonlinear ones, we investigate adversarial training with a variety of adversarial perturbations in a unified manner. Specifically, we show that the direction of the limit point of parameters converges to a KKT point of a constrained optimization problem that aims to maximize the margin for adversarial examples. Additionally, as an application of this general result for two special linear homogeneous DNNs, diagonal linear networks and linear convolutional networks, we show that adversarial training with $\ell _{p}$ℓp-norm perturbation equivalently minimizes an interpolation norm that depends on the depth, the architecture, and the value of $p$p in the predictor space. Extensive experiments are conducted to verify theoretical claims. Our results theoretically provide the basis for the longstanding folklore Madry et al. 2018 that adversarial training modifies the decision boundary by utilizing adversarial examples to improve robustness, and potentially provide insights for designing new robust training strategies.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
cdercder应助科研通管家采纳,获得10
4秒前
小么完成签到 ,获得积分10
5秒前
zhoudada发布了新的文献求助10
6秒前
12秒前
冲冲冲完成签到 ,获得积分10
12秒前
有志者发布了新的文献求助10
17秒前
危莉完成签到 ,获得积分10
24秒前
如泣草芥完成签到,获得积分10
27秒前
鲁大海完成签到 ,获得积分10
29秒前
小黄完成签到 ,获得积分20
29秒前
小鱼完成签到 ,获得积分10
31秒前
t铁核桃1985完成签到 ,获得积分0
32秒前
牡蛎牡蛎粥完成签到 ,获得积分10
34秒前
1分钟前
1分钟前
1分钟前
南风完成签到 ,获得积分10
1分钟前
郑征完成签到,获得积分10
1分钟前
xianyaoz完成签到 ,获得积分0
1分钟前
黄花菜完成签到 ,获得积分0
1分钟前
深情安青应助青乔采纳,获得10
2分钟前
2分钟前
cdercder应助科研通管家采纳,获得10
2分钟前
Xuan完成签到,获得积分10
2分钟前
听流沙完成签到 ,获得积分10
2分钟前
Jzag完成签到 ,获得积分10
2分钟前
2分钟前
青木完成签到 ,获得积分10
2分钟前
道交法发布了新的文献求助10
2分钟前
2分钟前
2分钟前
amm完成签到 ,获得积分10
2分钟前
2分钟前
www完成签到 ,获得积分10
2分钟前
oldlion完成签到,获得积分10
2分钟前
钱都来完成签到 ,获得积分10
2分钟前
栀蓝完成签到 ,获得积分10
2分钟前
guo完成签到,获得积分10
2分钟前
pei完成签到 ,获得积分10
2分钟前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Evidence Summary. Injection (subcutaneous):op- timal administration 1000
悉尼大学博士学位论文,题目:Modelling and testing of one-sided stitched laminated composites. 作者:Kristopher P. Plain 700
Matrix Methods in Data Mining and Pattern Recognition Second Edition 610
Curating Socialism: A Handbook of International Art Exhibitions 1947-1989 530
Lengua e imagen en la comunicación digital 500
文献求助-中国李庄学术史 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7474737
求助须知:如何正确求助?哪些是违规求助? 9069311
关于积分的说明 19336168
捐赠科研通 7093567
什么是DOI,文献DOI怎么找? 3246325
关于科研通互助平台的介绍 2415445
邀请新用户注册赠送积分活动 2231313