Adaptive precision layering for efficient adversarial training of deep learning models in intelligent vehicles
Manzoor Hussain, Zhengyu Shang, Jang‐Eui Hong · Expert Systems with Applications · 2025
Adversarial training is a widely used technique to enhance the robustness of deep learning models. However, it is computationally expensive due to the need to calculate gradients for generating adversarial samples. While fast gradient sign method (FGSM)-based adversarial training is commonly employed to improve model robustness, it still incurs significant training time and computational overhead compared to standard training. Moreover, the robustness of models trained with FGSM-based adversarial training often remains unsatisfactory. Among the most efficient training techniques, mixed precision-based training reduces computational overheads by accelerating the standard training process. However, applying mixed precision to adversarial training does not reduce computational overheads and increase robustness. Thus, this article proposes a novel adaptive precision layering-based adversarial training and gradient accumulation method to reduce the computational cost. The proposed method efficiently assigns precision levels ( single and half precision ) to each model layer based on its sensitivity to precision loss. The less sensitive layers are assigned with half-precision, and the output layer is assigned with single precision. The perturbations are generated during the adversarial training by leveraging the fast gradient sign method with a random initialization technique. Additionally, the accumulation steps are also adaptively set based on the gradient flow and stability analysis. The adaptive precision layering accelerates the utilization of the graphics processing unit, and the efficient gradient accumulation method avoids unnecessary gradient calculation, thus reducing training time. By adaptively assigning the precision, gradient accumulation, and random initialization, we effectively solve three major problems in adversarial training: 1) significantly reduce the training time overheads, 2) solve the catastrophic overfitting, and 3) improve the robustness of the target models. Experimental evaluations on three state-of-the-art self-driving car models demonstrate an excellent improvement in adversarial robustness while significantly reducing the computational overheads.