信息瓶颈模型对抗鲁棒性的再审视
机器学习
2021-07-14 v1
摘要
我们研究了用于分类的信息瓶颈模型的对抗鲁棒性。先前的工作表明,用信息瓶颈训练的模型的鲁棒性可以优于对抗训练。我们在多种白盒 攻击下的评估表明,信息瓶颈本身并非一种强防御策略,且先前的结果很可能受到梯度混淆的影响。
引用
@article{arxiv.2107.05712,
title = {A Closer Look at the Adversarial Robustness of Information Bottleneck Models},
author = {Iryna Korshunova and David Stutz and Alexander A. Alemi and Olivia Wiles and Sven Gowal},
journal= {arXiv preprint arXiv:2107.05712},
year = {2021}
}