Learning with a Strong Adversary
Ruitong Huang Bing Xu Dale Schuurmans Csaba Szepesvári Affiliation: Department of Computer Science Affiliation: University of Alberta Affiliation: Edmonton, AB T6G 2E8, Canada Email:
Abstract
The robustness of neural networks to intended perturbations has recently attracted significant attention. In this paper, we propose a new method, learning with a strong adversary, that learns robust classifiers from supervised data by generating adversarial examples as an intermediate step. A new and simple way of finding adversarial examples is presented that is empirically stronger than existing approaches in terms of the accuracy reduction as a function of perturbation magnitude. Experimental results demonstrate that resulting learning method greatly improves the robustness of the classification models produced.
原文 arXiv:1511.03034;中英对照 + 大白话阅读 https://aha.fim.ai/paper/1511.03034v6