Data Augmentation and Graph Regularization for Adversarial Training

Samet Bayram, Kenneth E. Barner · Artificial intelligence · 2024

This chapter explores innovative regularization strategies designed to enhance the resilience and accuracy of deep learning models against adversarial attacks, focusing particularly on graph-based methods. At the forefront is Graph Regularized Adversarial Training (GReAT), a pioneering approach that integrates graph-based regularization with adversarial training to exploit the underlying data structure for improved model robustness. By leveraging relationships among related samples, including augmented ones, GReAT significantly enhances performance. This chapter introduces enhanced versions of GReAT (Augmented GReAT) that incorporate standard data augmentation techniques. These extensions further enrich model training by diversifying the training examples within the graph framework. These methods aim to fortify models against sophisticated adversarial perturbations and improve generalization to new unseen datasets. Our comprehensive evaluations on benchmark datasets such as CIFAR-10 and SVHN demonstrate that these techniques, particularly Augmented GReAT, outperform traditional adversarial training methods. Augmented GReAT shows significant performance gains, achieving up to a 12% increase against PGD attacks on CIFAR-10 and 6.3% on SVHN. This chapter details the underlying theories and implementation of these augmented graph-based regularization techniques and thoroughly analyzes their impact through extensive experimental results. By integrating graph structures and data augmentation into the training process, we showcase significant advancements in neural networks’ robustness and predictive accuracy, setting new benchmarks in the field.

Read the paper · More papers on PaperTik