Pith. sign in

REVIEW 1 cited by

Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1910.08051 v1 pith:EH4SHBVB submitted 2019-10-17 cs.LG cs.CVstat.ML

classification cs.LGcs.CVstat.ML
keywords trainingadversarialaroundperturbationsamplesaccuracyadaptiveapproach
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Adversarial training is by far the most successful strategy for improving robustness of neural networks to adversarial attacks. Despite its success as a defense mechanism, adversarial training fails to generalize well to unperturbed test set. We hypothesize that this poor generalization is a consequence of adversarial training with uniform perturbation radius around every training sample. Samples close to decision boundary can be morphed into a different class under a small perturbation budget, and enforcing large margins around these samples produce poor decision boundaries that generalize poorly. Motivated by this hypothesis, we propose instance adaptive adversarial training -- a technique that enforces sample-specific perturbation margins around every training sample. We show that using our approach, test accuracy on unperturbed samples improve with a marginal drop in robustness. Extensive experiments on CIFAR-10, CIFAR-100 and Imagenet datasets demonstrate the effectiveness of our proposed approach.

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. A unifying Bayesian framework for adversarial robustness

    stat.ML 2025-10 conditional novelty 6.0 of 10

    A Bayesian model of adversarial perturbations yields reactive and proactive defenses, with adversarial training and randomized smoothing as limiting cases.

Pith tools