Adaptive Perturbation-Driven Adversarial Training

Shuai Li, Xiaoguang Ma, Shancheng Jiang, Lu Meng, Suqi Zhang · 2024

Recently, convolutional neural networks (CNNs) had achieved remarkable success across various domains. However, existing research indicated they were vulnerable to adversarial examples (AEs), raising concerns on model robustness. While adversarial training (AT) was an effective way to improve robustness of models, it always resulted in decline of generalization. In this paper, we proposed Adaptive Perturbation-Driven Adversarial Training (APDAT) to enhance robustness while maintaining high generalization, which placed networks into a dynamic learning environment, generating adaptive data-level perturbations and providing a continuously updated criterion informed by loss information collections, which handled the disadvantage of fixed perturbation sizes in conventional AT methods and reduced reliance on external transfer mechanisms. Extensive testing on the dermatology HAM10000 dataset demonstrated that APDAT achieved superior improvements in robustness and generalization, while also demonstrating superior interpretability, indicating that our method was a promising and generic AT method.

Read the paper · More papers on PaperTik