CASIA OpenIR  > 模式识别国家重点实验室  > 模式分析与学习
Adversarial training with distribution normalization and margin balance
Cheng, Zhen1,2; Zhu, Fei1,2; Zhang, Xu-Yao1,2; Liu, Cheng-Lin1,2
Source PublicationPATTERN RECOGNITION
ISSN0031-3203
2023-04-01
Volume136Pages:11
Corresponding AuthorZhang, Xu-Yao(xyz@nlpr.ia.ac.cn)
AbstractAdversarial training is the most effective method to improve adversarial robustness. However, it does not explicitly regularize the feature space during training. Adversarial attacks usually move a sample it-eratively along the direction which causes the steepest ascent of classification loss by crossing decision boundary. To alleviate this problem, we propose to regularize the distributions of different classes to increase the difficulty of finding an attacking direction. Specifically, we propose two strategies named Distribution Normalization (DN) and Margin Balance (MB) for adversarial training. The purpose of DN is to normalize the features of each class to have identical variance in every direction, in order to elimi-nate easy-to-attack intra-class directions. The purpose of MB is to balance the margins between different classes, making it harder to find confusing class directions (i.e., those with smaller margins) to attack. When integrated with adversarial training, our method can significantly improve adversarial robustness. Extensive experiments under white-box, black-box, and adaptive attacks demonstrate the effectiveness of our method over other state-of-the-art methods.(c) 2022 Elsevier Ltd. All rights reserved.
KeywordAdversarial robustness Adversarial training Distribution normalization Margin balance
DOI10.1016/j.patcog.2022.109182
Indexed BySCI
Language英语
Funding ProjectNational Key Research and Development Program[2018AAA0100400] ; National Natural Science Foundation of China (NSFC)[U20A20223] ; National Natural Science Foundation of China (NSFC)[62222609] ; National Natural Science Foundation of China (NSFC)[62076236] ; National Natural Science Foundation of China (NSFC)[61721004] ; Key Research Program of Frontier Sciences of Chinese Academy of Sciences[ZDBS-LY-7004] ; Youth Innovation Promotion Association of Chinese Academy of Sciences[2019141]
Funding OrganizationNational Key Research and Development Program ; National Natural Science Foundation of China (NSFC) ; Key Research Program of Frontier Sciences of Chinese Academy of Sciences ; Youth Innovation Promotion Association of Chinese Academy of Sciences
WOS Research AreaComputer Science ; Engineering
WOS SubjectComputer Science, Artificial Intelligence ; Engineering, Electrical & Electronic
WOS IDWOS:000891819300004
PublisherELSEVIER SCI LTD
Citation statistics
Document Type期刊论文
Identifierhttp://ir.ia.ac.cn/handle/173211/50828
Collection模式识别国家重点实验室_模式分析与学习
Corresponding AuthorZhang, Xu-Yao
Affiliation1.Chinese Acad Sci, Natl Lab Pattern Recognit NLPR, Inst Automat, Beijing 100190, Peoples R China
2.Univ Chinese Acad Sci UCAS, Sch Artificial Intelligence, Beijing 100049, Peoples R China
First Author AffilicationChinese Acad Sci, Inst Automat, Natl Lab Pattern Recognit, Beijing 100190, Peoples R China
Corresponding Author AffilicationChinese Acad Sci, Inst Automat, Natl Lab Pattern Recognit, Beijing 100190, Peoples R China
Recommended Citation
GB/T 7714
Cheng, Zhen,Zhu, Fei,Zhang, Xu-Yao,et al. Adversarial training with distribution normalization and margin balance[J]. PATTERN RECOGNITION,2023,136:11.
APA Cheng, Zhen,Zhu, Fei,Zhang, Xu-Yao,&Liu, Cheng-Lin.(2023).Adversarial training with distribution normalization and margin balance.PATTERN RECOGNITION,136,11.
MLA Cheng, Zhen,et al."Adversarial training with distribution normalization and margin balance".PATTERN RECOGNITION 136(2023):11.
Files in This Item:
There are no files associated with this item.
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[Cheng, Zhen]'s Articles
[Zhu, Fei]'s Articles
[Zhang, Xu-Yao]'s Articles
Baidu academic
Similar articles in Baidu academic
[Cheng, Zhen]'s Articles
[Zhu, Fei]'s Articles
[Zhang, Xu-Yao]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[Cheng, Zhen]'s Articles
[Zhu, Fei]'s Articles
[Zhang, Xu-Yao]'s Articles
Terms of Use
No data!
Social Bookmark/Share
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.