Model Adversarial Attack and Defense Based on Network Reorganization
Xiaotong Cui, Jinyu Xiao, Wei Zheng · 2024
To address the tradeoff issues in adversarial training of deep neural networks, where enhancing one performance metric often compromises another; the gradual decrease in model robustness in the later stages of training; or the sudden drop in robustness after a specific training stage, etc. This article mainly starts from two perspectives: modifying the network architecture and applying improved adversarial training methods. By adding the CBAM dual attention mechanism and DropBlock regularization technology to the existing wide residual network WideResNet_22_10, the accuracy and robustness of the model are improved to a certain extent. Experimental results demonstrate that TRADES, an enhanced adversarial training approach, surpasses conventional methods in strengthening model resilience against powerful adversarial attacks.