The Quantitative Relationship between Adversarial Training and Robustness of CNN Model
Jie Wang, Minyan Lu, Jun Ai, Xueyuan Sun · 2020
With the increasing application of deep neural networks in security-critical systems, robustness becomes an important property for deep learning. However, deep neural networks are very vulnerable to perturbations, especially adversarial attacks. The adversarial training by adding adversarial examples to the training set has become a common method to improve the performance of deep neural networks. In this paper, based on the existing robustness metrics and indicators, we study the quantitative influence of adversarial training on the robustness of network-in-network and residual network, and the differences of indicators are compared. The experimental results show that adversarial training can affect the accuracy and robustness of CNN models, and the variation trends of testing accuracy and robustness are opposite.