Cooperation or Competition: Avoiding Player Domination for Multi-Target Robustness via Adaptive Budgets
Abstract: Despite incredible advances, deep learning has been shown to be susceptible to adversarial attacks. Numerous approaches have been proposed to train robust networks both empirically and certifiably. However, most of them defend against only a single type of attack, while recent work takes steps forward in defending against multiple attacks. In this paper, to understand multi-target robustness, we view this problem as a bargaining game in which different players (adversaries) negotiate to reach an agreement on a joint direction of parameter updating. We identify a phenomenon named player domination in the bargaining game, namely that the existing max-based approaches, such as MAX and MSD, do not converge. Based on our theoretical analysis, we design a novel framework that adjusts the budgets of different adversaries to avoid any player dominance. Experiments on standard benchmarks show that employing the proposed framework to the existing approaches significantly advances multi-target robustness.
- Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International Conference on Machine Learning, pages 274–283, 2018.
- Adversarial training and provable defenses: Bridging the gap. In International Conference on Learning Representations, 2020.
- Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In International Conference on Learning Representations, 2018.
- Accurate, reliable and fast robustness evaluation. In Advances in Neural Information Processing Systems, pages 12841–12851, 2019.
- Towards evaluating the robustness of neural networks. In IEEE symposium on security and privacy, pages 39–57, 2017.
- Class-aware robust adversarial training for object detection. In IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 10420–10429, 2021.
- Provable robustness against all adversarial lpsubscript𝑙𝑝l_{p}italic_l start_POSTSUBSCRIPT italic_p end_POSTSUBSCRIPT-perturbations for p≥1𝑝1p\geq 1italic_p ≥ 1. In International Conference on Learning Representations, 2020.
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International Conference on Machine Learning, pages 2206–2216, 2020.
- Imagenet: A large-scale hierarchical image database. In IEEE conference on computer vision and pattern recognition, pages 248–255, 2009.
- Adaptive Subgradient Methods for Online Learning and Stochastic Optimization. Journal of Machine Learning Research, 12(61):2121–2159, 2011.
- A Rotation and a Translation Suffice: Fooling CNNs with Simple Transformations. 2018.
- Intelligent driving intelligence test for autonomous vehicles with naturalistic and adversarial environment. Nature communications, 12(1):1–14, 2021.
- Fast and reliable evaluation of adversarial robustness with minimum-margin attack. In International Conference on Machine Learning, pages 7144–7163, 2022.
- Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations, 2015.
- Deep residual learning for image recognition. In IEEE Conference on Computer Vision and Pattern Recognition, pages 770–778, 2016.
- Deep Residual Learning for Image Recognition. In IEEE Conference on Computer Vision and Pattern Recognition, pages 770–778, 2016.
- Fooling detection alone is not enough: Adversarial attack against multiple object tracking. In International Conference on Learning Representations, 2020.
- Transfer of Adversarial Robustness Between Perturbation Types. In arxiv:1905.01034, 2019.
- Adversarial Logit Pairing. In arXiv:1803.06373, 2018.
- Adam: A method for stochastic optimization. In International Conference on Learning Representations, 2015.
- Learning multiple layers of features from tiny images. Technical report, Citeseer, 2009.
- Adversarial examples in the physical world. In International Conference on Learning Representations Workshop, 2017.
- Gradient-based learning applied to document recognition. Proceedings of the IEEE, 86(11):2278–2324, 1998.
- Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks. In International Conference on Machine Learning, pages 3866–3876, 2019.
- Towards deep learning models resistant to adversarial attacks. In International Conference on Learning Representations, 2018.
- Adversarial Robustness Against the Union of Multiple Perturbation Models. In International Conference on Machine Learning, pages 6640–6650, 2020.
- Logit pairing methods can fool gradient-based attacks. In NeurIPS 2018 Workshop on Security in Machine Learning, 2018.
- Mixup inference: Better exploiting mixup to defend adversarial attacks. In International Conference on Learning Representations, 2020.
- Bag of tricks for adversarial training. In International Conference on Learning Representations, 2021.
- Boosting adversarial training with hypersphere embedding. In Advances in Neural Information Processing Systems, pages 7779–7792, 2020.
- Distillation as a defense to adversarial perturbations against deep neural networks. In IEEE Symposium on Security and Privacy, pages 582–597, 2016.
- PyTorch: An Imperative Style, High-Performance Deep Learning Library. In Advances in Neural Information Processing Systems, pages 8024–8035, 2019.
- Certified Defenses against Adversarial Examples. In International Conference on Learning Representations, 2022.
- A stochastic approximation method. The annals of mathematical statistics, pages 400–407, 1951.
- Towards the first adversarially robust neural network model on MNIST. In International conference on Learning Representations, 2019.
- Are adversarial examples inevitable? In International Conference on Learning Representations, 2019.
- Informative dropout for robust representation learning: A shape-bias perspective. pages 8828–8839, 2020.
- Leslie N. Smith. A disciplined approach to neural network hyper-parameters: Part 1 - learning rate, batch size, momentum, and weight decay. In arXiv:1803.09820, 2018.
- Intriguing properties of neural networks. In International Conference on Learning Representations, 2014.
- William Thomson. Chapter 35 Cooperative models of bargaining. In Handbook of Game Theory with Economic Applications, volume 2, pages 1237–1284. Elsevier, 1994.
- Adversarial Training and Robustness for Multiple Perturbations. In Advances in Neural Information Processing Systems, pages 5858–5868, 2019.
- Ensemble adversarial training: Attacks and defenses. In International Conference on Learning Representations, 2018.
- Robustness May Be at Odds with Accuracy. In International Conference on Learning Representations, 2019.
- Once-for-all adversarial training: In-situ tradeoff between robustness and accuracy for free. In Advances in Neural Information Processing Systems, 2020.
- Self-ensemble adversarial training for improved robustness. In International Conference on Learning Representations, 2022.
- Probabilistic margins for instance reweighting in adversarial training. In Advances in Neural Information Processing Systems, pages 23258–23269, 2021.
- Searching privately by imperceptible lying: A novel private hashing method with differential privacy. In ACM International Conference on Multimedia, page 2700–2709, 2020.
- An adversarial domain adaptation network for cross-domain fine-grained recognition. In IEEE Winter Conference on Applications of Computer Vision, pages 1217–1225, 2020.
- Provable Defenses against Adversarial Examples via the Convex Outer Adversarial Polytope. In International Conference on Machine Learning, pages 5286–5295, 2018.
- Adversarial weight perturbation helps robust generalization. In Advances in Neural Information Processing Systems, pages 2958–2969, 2020.
- Adversarial weight perturbation improves generalization in graph neural network. arXiv preprint arXiv:2212.04983, 2022.
- Retrievalguard: Provably robust 1-nearest neighbor image retrieval. In International Conference on Machine Learning, pages 24266–24279. PMLR, 2022.
- Building robust ensembles via margin boosting. In International Conference on Machine Learning, pages 26669–26692, 2022.
- You only propagate once: Accelerating adversarial training via maximal principle. In Advances in Neural Information Processing Systems, pages 227–238, 2019.
- Theoretically principled trade-off between robustness and accuracy. In International Conference on Machine Learning, pages 7472–7482, 2019.
- Attacks which do not kill training make adversarial learning stronger. In International Conference on Machine Learning, 2020.
- Adversarial robustness through the lens of causality. In International Conference on Learning Representations, 2022.
- Efficient adversarial training with transferable adversarial examples. In IEEE/CVF Conference on Computer Vision and Pattern Recognition, pages 1178–1187, 2020.
Paper Prompts
Sign up for free to create and run prompts on this paper.