Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
110 tokens/sec
GPT-4o
56 tokens/sec
Gemini 2.5 Pro Pro
44 tokens/sec
o3 Pro
6 tokens/sec
GPT-4.1 Pro
47 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Frequency Regularization for Improving Adversarial Robustness (2212.12732v1)

Published 24 Dec 2022 in cs.CV

Abstract: Deep neural networks are incredibly vulnerable to crafted, human-imperceptible adversarial perturbations. Although adversarial training (AT) has proven to be an effective defense approach, we find that the AT-trained models heavily rely on the input low-frequency content for judgment, accounting for the low standard accuracy. To close the large gap between the standard and robust accuracies during AT, we investigate the frequency difference between clean and adversarial inputs, and propose a frequency regularization (FR) to align the output difference in the spectral domain. Besides, we find Stochastic Weight Averaging (SWA), by smoothing the kernels over epochs, further improves the robustness. Among various defense schemes, our method achieves the strongest robustness against attacks by PGD-20, C&W and Autoattack, on a WideResNet trained on CIFAR-10 without any extra data.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (4)
  1. Binxiao Huang (13 papers)
  2. Chaofan Tao (27 papers)
  3. Rui Lin (36 papers)
  4. Ngai Wong (82 papers)
Citations (4)

Summary

We haven't generated a summary for this paper yet.