Matches in SemOpenAlex for { <https://semopenalex.org/work/W2996568780> ?p ?o ?g. }
- W2996568780 abstract "Adversarial training is one of the main defenses against adversarial attacks. In this paper, we provide the first rigorous study on diagnosing elements of large-scale adversarial training on ImageNet, which reveals two intriguing properties. First, we study the role of normalization. Batch normalization (BN) is a crucial element for achieving state-of-the-art performance on many vision tasks, but we show it may prevent networks from obtaining strong robustness in adversarial training. One unexpected observation is that, for models trained with BN, simply removing clean images from training data largely boosts adversarial robustness, i.e., 18.3%. We relate this phenomenon to the hypothesis that clean images and adversarial images are drawn from two different domains. This two-domain hypothesis may explain the issue of BN when training with a mixture of clean and adversarial images, as estimating normalization statistics of this mixture distribution is challenging. Guided by this two-domain hypothesis, we show disentangling the mixture distribution for normalization, i.e., applying separate BNs to clean and adversarial images for statistics estimation, achieves much stronger robustness. Additionally, we find that enforcing BNs to behave consistently at training and testing can further enhance robustness. Second, we study the role of network capacity. We find our so-called deep networks are still shallow for the task of adversarial learning. Unlike traditional classification tasks where accuracy is only marginally improved by adding more layers to deep networks (e.g., ResNet-152), adversarial training exhibits a much stronger demand on deeper networks to achieve higher adversarial robustness. This robustness improvement can be observed substantially and consistently even by pushing the network capacity to an unprecedented scale, i.e., ResNet-638." @default.
- W2996568780 created "2019-12-26" @default.
- W2996568780 creator A5022344556 @default.
- W2996568780 creator A5086706224 @default.
- W2996568780 date "2020-04-30" @default.
- W2996568780 modified "2023-09-27" @default.
- W2996568780 title "Intriguing Properties of Adversarial Training at Scale" @default.
- W2996568780 cites W1836465849 @default.
- W2996568780 cites W2097117768 @default.
- W2996568780 cites W2099471712 @default.
- W2996568780 cites W2194775991 @default.
- W2996568780 cites W2319356411 @default.
- W2996568780 cites W2502312327 @default.
- W2996568780 cites W2561975083 @default.
- W2996568780 cites W2593892853 @default.
- W2996568780 cites W2594867206 @default.
- W2996568780 cites W2791953061 @default.
- W2996568780 cites W2807108439 @default.
- W2996568780 cites W2884821828 @default.
- W2996568780 cites W2898152545 @default.
- W2996568780 cites W2907518016 @default.
- W2996568780 cites W2912237282 @default.
- W2996568780 cites W2942630857 @default.
- W2996568780 cites W2942836458 @default.
- W2996568780 cites W2947294642 @default.
- W2996568780 cites W2954042061 @default.
- W2996568780 cites W2962729158 @default.
- W2996568780 cites W2962872506 @default.
- W2996568780 cites W2963207607 @default.
- W2996568780 cites W2963446712 @default.
- W2996568780 cites W2963539306 @default.
- W2996568780 cites W2963744840 @default.
- W2996568780 cites W2964153729 @default.
- W2996568780 cites W2964253222 @default.
- W2996568780 cites W2970049488 @default.
- W2996568780 cites W2970317235 @default.
- W2996568780 cites W2970451906 @default.
- W2996568780 cites W2970457724 @default.
- W2996568780 cites W2970680991 @default.
- W2996568780 cites W2971316968 @default.
- W2996568780 cites W2980728855 @default.
- W2996568780 cites W2989929945 @default.
- W2996568780 cites W3004298045 @default.
- W2996568780 cites W3035743198 @default.
- W2996568780 hasPublicationYear "2020" @default.
- W2996568780 type Work @default.
- W2996568780 sameAs 2996568780 @default.
- W2996568780 citedByCount "55" @default.
- W2996568780 countsByYear W29965687802019 @default.
- W2996568780 countsByYear W29965687802020 @default.
- W2996568780 countsByYear W29965687802021 @default.
- W2996568780 crossrefType "proceedings-article" @default.
- W2996568780 hasAuthorship W2996568780A5022344556 @default.
- W2996568780 hasAuthorship W2996568780A5086706224 @default.
- W2996568780 hasConcept C104317684 @default.
- W2996568780 hasConcept C108583219 @default.
- W2996568780 hasConcept C119857082 @default.
- W2996568780 hasConcept C136886441 @default.
- W2996568780 hasConcept C144024400 @default.
- W2996568780 hasConcept C153180895 @default.
- W2996568780 hasConcept C154945302 @default.
- W2996568780 hasConcept C185592680 @default.
- W2996568780 hasConcept C19165224 @default.
- W2996568780 hasConcept C2984842247 @default.
- W2996568780 hasConcept C37736160 @default.
- W2996568780 hasConcept C41008148 @default.
- W2996568780 hasConcept C51632099 @default.
- W2996568780 hasConcept C55493867 @default.
- W2996568780 hasConcept C63479239 @default.
- W2996568780 hasConceptScore W2996568780C104317684 @default.
- W2996568780 hasConceptScore W2996568780C108583219 @default.
- W2996568780 hasConceptScore W2996568780C119857082 @default.
- W2996568780 hasConceptScore W2996568780C136886441 @default.
- W2996568780 hasConceptScore W2996568780C144024400 @default.
- W2996568780 hasConceptScore W2996568780C153180895 @default.
- W2996568780 hasConceptScore W2996568780C154945302 @default.
- W2996568780 hasConceptScore W2996568780C185592680 @default.
- W2996568780 hasConceptScore W2996568780C19165224 @default.
- W2996568780 hasConceptScore W2996568780C2984842247 @default.
- W2996568780 hasConceptScore W2996568780C37736160 @default.
- W2996568780 hasConceptScore W2996568780C41008148 @default.
- W2996568780 hasConceptScore W2996568780C51632099 @default.
- W2996568780 hasConceptScore W2996568780C55493867 @default.
- W2996568780 hasConceptScore W2996568780C63479239 @default.
- W2996568780 hasLocation W29965687801 @default.
- W2996568780 hasOpenAccess W2996568780 @default.
- W2996568780 hasPrimaryLocation W29965687801 @default.
- W2996568780 hasRelatedWork W2108598243 @default.
- W2996568780 hasRelatedWork W2163605009 @default.
- W2996568780 hasRelatedWork W2194775991 @default.
- W2996568780 hasRelatedWork W2243397390 @default.
- W2996568780 hasRelatedWork W2774644650 @default.
- W2996568780 hasRelatedWork W2912237282 @default.
- W2996568780 hasRelatedWork W2913848079 @default.
- W2996568780 hasRelatedWork W2962872506 @default.
- W2996568780 hasRelatedWork W2963060032 @default.
- W2996568780 hasRelatedWork W2963143631 @default.
- W2996568780 hasRelatedWork W2963207607 @default.
- W2996568780 hasRelatedWork W2963857521 @default.
- W2996568780 hasRelatedWork W2964153729 @default.