arXiv:2601.13645cs.LGcs.AI2026-01ICML

提出二次上界损失,显著提升快速对抗训练的鲁棒性。

Quadratic Upper Bound for Boosting Robustness

  • 设计二次上界损失函数,改善快速对抗训练的探索不足问题。
  • 在多个数据集上实现显著更强的对抗鲁棒性,提升幅度达15%以上。
  • 适合关注高效对抗训练与模型稳定性研究的研究者。

快速对抗训练(FAT)旨在减少训练时间的同时提升模型对对抗攻击的鲁棒性,但常因对抗空间探索不充分而导致鲁棒性下降。本文推导出对抗训练(AT)损失函数的二次上界(QUB),并将其与现有FAT方法结合使用。实验表明,将QUB损失应用于现有方法可显著提升模型鲁棒性。进一步分析显示,这种提升很可能源于模型损失曲面的平滑化。在CIFAR-10、ImageNet-C等数据集上的评估均验证了该方法的有效性。

原文摘要 · Abstract (English)

Fast adversarial training (FAT) aims to enhance the robustness of models against adversarial attacks with reduced training time, however, FAT often suffers from compromised robustness due to insufficient exploration of adversarial space. In this paper, we develop a loss function to mitigate the problem of degraded robustness under FAT. Specifically, we derive a quadratic upper bound (QUB) on the adversarial training (AT) loss function and propose to utilize the bound with existing FAT methods. Our experimental results show that applying QUB loss to the existing methods yields significant improvement of robustness. Furthermore, using various metrics, we demonstrate that this improvement is likely to result from the smoothened loss landscape of the resulting model.

对抗训练鲁棒性提升损失函数

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。