通过损失景观几何理解对抗鲁棒性
机器学习
2019-07-23 v1 密码学与安全
机器学习
摘要
解释和改进深度学习泛化能力的努力引发了在正则化技术以及损失曲面几何可视化技术两方面的研究。后者与社区中普遍存在的直觉有关,即更平坦的局部最优会导致更低的泛化误差。在本文中,我们利用最先进的损失曲面可视化“滤波器归一化”技术,定性地理解使用对抗训练数据增强作为显式正则化技术的后果。令我们惊讶的是,我们发现这种经常部署的对抗增强技术实际上并未产生“更平坦”的损失景观,这需要重新思考对抗训练泛化,以及泛化与损失景观几何之间的关系。
引用
@article{arxiv.1907.09061,
title = {Understanding Adversarial Robustness Through Loss Landscape Geometries},
author = {Vinay Uday Prabhu and Dian Ang Yap and Joyce Xu and John Whaley},
journal= {arXiv preprint arXiv:1907.09061},
year = {2019}
}
备注
Presented at the ICML 2019 Workshop on Uncertainty and Robustness in Deep Learning, and CVPR 2019 Workshop on The Bright and Dark Sides of Computer Vision: Challenges and Opportunities for Privacy and Security (CV-COPS)