English

On Norm-Agnostic Robustness of Adversarial Training

Machine Learning 2019-05-17 v1 Cryptography and Security Machine Learning

Abstract

Adversarial examples are carefully perturbed in-puts for fooling machine learning models. A well-acknowledged defense method against such examples is adversarial training, where adversarial examples are injected into training data to increase robustness. In this paper, we propose a new attack to unveil an undesired property of the state-of-the-art adversarial training, that is it fails to obtain robustness against perturbations in 2\ell_2 and \ell_\infty norms simultaneously. We discuss a possible solution to this issue and its limitations as well.

Keywords

Cite

@article{arxiv.1905.06455,
  title  = {On Norm-Agnostic Robustness of Adversarial Training},
  author = {Bai Li and Changyou Chen and Wenlin Wang and Lawrence Carin},
  journal= {arXiv preprint arXiv:1905.06455},
  year   = {2019}
}

Comments

4 pages, 2 figures, presented at the ICML 2019 Workshop on Uncertainty and Robustness in Deep Learning. arXiv admin note: text overlap with arXiv:1809.03113