Improving Ensemble Robustness by Collaboratively Promoting and Demoting Adversarial Robustness

09/21/2020
by   Anh Bui, et al.
8

Ensemble-based adversarial training is a principled approach to achieve robustness against adversarial attacks. An important technique of this approach is to control the transferability of adversarial examples among ensemble members. We propose in this work a simple yet effective strategy to collaborate among committee models of an ensemble model. This is achieved via the secure and insecure sets defined for each model member on a given sample, hence help us to quantify and regularize the transferability. Consequently, our proposed framework provides the flexibility to reduce the adversarial transferability as well as to promote the diversity of ensemble members, which are two crucial factors for better robustness in our ensemble approach. We conduct extensive and comprehensive experiments to demonstrate that our proposed method outperforms the state-of-the-art ensemble baselines, at the same time can detect a wide range of adversarial examples with a nearly perfect accuracy.

READ FULL TEXT

page 13

page 14

04/01/2021

TRS: Transferability Reduced Ensemble via Encouraging Gradient Diversity and Model Smoothness

Adversarial Transferability is an intriguing property of adversarial exa...
09/16/2022

Robust Ensemble Morph Detection with Domain Generalization

Although a substantial amount of studies is dedicated to morph detection...
01/25/2019

Improving Adversarial Robustness via Promoting Ensemble Diversity

Though deep neural networks have achieved significant progress on variou...
09/28/2020

Where Does the Robustness Come from? A Study of the Transformation-based Ensemble Defence

This paper aims to provide a thorough study on the effectiveness of the ...
07/21/2023

Improving Transferability of Adversarial Examples via Bayesian Attacks

This paper presents a substantial extension of our work published at ICL...
08/04/2020

TREND: Transferability based Robust ENsemble Design

Deep Learning models hold state-of-the-art performance in many fields, b...
09/21/2020

Adversarial Training with Stochastic Weight Average

Adversarial training deep neural networks often experience serious overf...

Code Repositories

Crossing-Collaborative-Ensemble

Tensorflow implementation of the AAAI-21 paper "Improving Ensemble Robustness by Collaboratively Promoting and Demoting Robustness"


view repo

Please sign up or login with your details

Forgot password? Click here to reset