论文标题

实现对抗性鲁棒性需要一个活跃的老师

Achieving Adversarial Robustness Requires An Active Teacher

论文作者

Ma, Chao, Ying, Lexing

论文摘要

通过将数据生成器和标签生成器(我们称为老师)解耦,对对抗性示例和对抗性鲁棒性有了新的了解。在我们的框架中,对抗性的鲁棒性是一个有条件的概念 - 学生模型并不是绝对健壮的,而是关于老师的强大概念。基于新的理解,我们声称存在对抗性示例,因为学生无法从培训数据中获得足够的教师信息。比较了各种实现鲁棒性的方法。理论和数值证据表明,有效地实现鲁棒性,可能有必要为学生提供信息。

A new understanding of adversarial examples and adversarial robustness is proposed by decoupling the data generator and the label generator (which we call the teacher). In our framework, adversarial robustness is a conditional concept---the student model is not absolutely robust, but robust with respect to the teacher. Based on the new understanding, we claim that adversarial examples exist because the student cannot obtain sufficient information of the teacher from the training data. Various ways of achieving robustness is compared. Theoretical and numerical evidence shows that to efficiently attain robustness, a teacher that actively provides its information to the student may be necessary.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源