RegWeight: Adversarial Training based on Dynamically-Adjusted Regularization Weights
Yunfeng Lu, Samuel Thien, Xinxin Fan, Yanfang Liu, Bin Liu · 2022
The recent studies have evidenced that, for a target deep learning model, the accuracy of classification on adversarial examples will tend to decline while the performance on natural (original) examples becomes better. We find out that the behind reasons of such problem stems from the overfitting phenomenon. To mitigate this predicament, we in this paper propose a regularization-weight learning method RegWeight to dynamically adjust the classification boundaries over different classes. A set of experiments using two commonly-used datasets also validate the effectiveness of our proposed method, the experimental results show that our proposed RegWeight can validly promote the accuracy of classification on adversarial examples while at the same time retaining a little decreasing-level on the accuracy of classification on natural examples.