English

Adversarial Training is a Form of Data-dependent Operator Norm Regularization

Machine Learning 2020-10-26 v5 Machine Learning

Abstract

We establish a theoretical link between adversarial training and operator norm regularization for deep neural networks. Specifically, we prove that p\ell_p-norm constrained projected gradient ascent based adversarial training with an q\ell_q-norm loss on the logits of clean and perturbed inputs is equivalent to data-dependent (p, q) operator norm regularization. This fundamental connection confirms the long-standing argument that a network's sensitivity to adversarial examples is tied to its spectral properties and hints at novel ways to robustify and defend against adversarial attacks. We provide extensive empirical evidence on state-of-the-art network architectures to support our theoretical results.

Keywords

Cite

@article{arxiv.1906.01527,
  title  = {Adversarial Training is a Form of Data-dependent Operator Norm Regularization},
  author = {Kevin Roth and Yannic Kilcher and Thomas Hofmann},
  journal= {arXiv preprint arXiv:1906.01527},
  year   = {2020}
}

Comments

NeurIPS2020

R2 v1 2026-06-23T09:41:36.845Z