Pith. sign in

REVIEW 2 cited by

Smooth Adversarial Training

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2006.14536 v2 pith:7LHGQQ3S submitted 2020-06-25 cs.LG cs.CVcs.NE

classification cs.LGcs.CVcs.NE
keywords adversarialtrainingrobustnessaccuracysmoothnetworksactivationbelieved
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

It is commonly believed that networks cannot be both accurate and robust, that gaining robustness means losing accuracy. It is also generally believed that, unless making networks larger, network architectural elements would otherwise matter little in improving adversarial robustness. Here we present evidence to challenge these common beliefs by a careful study about adversarial training. Our key observation is that the widely-used ReLU activation function significantly weakens adversarial training due to its non-smooth nature. Hence we propose smooth adversarial training (SAT), in which we replace ReLU with its smooth approximations to strengthen adversarial training. The purpose of smooth activation functions in SAT is to allow it to find harder adversarial examples and compute better gradient updates during adversarial training. Compared to standard adversarial training, SAT improves adversarial robustness for "free", i.e., no drop in accuracy and no increase in computational cost. For example, without introducing additional computations, SAT significantly enhances ResNet-50's robustness from 33.0% to 42.3%, while also improving accuracy by 0.9% on ImageNet. SAT also works well with larger networks: it helps EfficientNet-L1 to achieve 82.2% accuracy and 58.6% robustness on ImageNet, outperforming the previous state-of-the-art defense by 9.5% for accuracy and 11.6% for robustness. Models are available at https://github.com/cihangxie/SmoothAdversarialTraining.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Robustness as Architecture: Designing IQA Models to Withstand Adversarial Perturbations

    cs.CV 2025-06 conditional novelty 5.0 of 10

    An NR-IQA defense built from an FFT-domain orthogonal block, 10% pruning, and fine-tuning lowers adversarial AbsGain on some models with a modest SROCC decline, but the reported gains are mixed across architectures.

  2. SDN-Based False Data Detection With Its Mitigation and Machine Learning Robustness for In-Vehicle Networks

    cs.LG 2025-06 reject novelty 4.0 of 10

    An SDN-based FDDMS with LSTM detects and mitigates false data injection in CAN networks and claims robustness against four adversarial attacks.

Pith tools