Impact of Adversarial Training on the Robustness of Deep Neural Networks

Jaechul Roh · 2022 IEEE 5th International Conference on Information Systems and Computer Aided Education (ICISCAE) · 2022

Recently, adversarial attack has received a decent degree of attention in the image domain after showing a high attack success rate due to their continuous characteristic. Several experiments have demonstrated a sharp drop in classification accuracy after evaluating the model with adversarial examples. While the number of research papers on different types of attacks has been flourishing, the method of adversarial training is still not established as the “classic” way of training the model. Most pre-trained models that could be downloaded easily from various websites are trained with clean data, which means such models will have high vulnerability to real-life images that mostly contain small noises. In this paper, we experimented with different types of adversarial training methods and observe how each one of them influenced the robustness of the deep learning model. Experiments demonstrate the comparison between each method in defending the modified Resnet-18 against perturbed histopathological images on diagnosing metastatic cancer.

Read the paper · More papers on PaperTik