Adversarial Training Based on Dimension Extension of Label Coding
Yanbiao Hao, Jinhui Li, Jianting Zhang · 2023
Facing the threat of adversarial samples, adversarial training comes into being. Since adversarial samples and clean samples obey different data distributions, it is difficult to weigh the clean classification accuracy and robustness of the adversarial training model. To solve this problem, we propose an adversarial training method based on dimension extension of label coding. Specifically, we first modify the target classifier model by replacing batch normalization with group normalization unrelated to batch data, so that the normalization operation of features is no longer related to the statistical characteristics of samples. Secondly, in view of the difference of samples under the same class, the label coding dimension extension is introduced to enlarge the distance between classes while reasonably considering the distance within the label class, so as to make the adversarial training objectives clearer. Finally, an auxiliary classification head in parallel with the original classification head of the target classifier is designed to provide feasibility for training the model with extended labels in the training stage. Experiments have been carried out to demonstrate the effectiveness of our proposed adversarial training method.