While leveraging additional training data is well established to improve adversarial robustness, it incurs the unavoidable cost of data collection and the heavy computation to train models. To mitigate the costs, we propose Guided Adversarial Training (GAT), a novel adversarial training technique that exploits auxiliary tasks under a limited set of training data. Our approach extends single-task models into multi-task models during the min-max optimization of adversarial training, and drives the loss optimization with a regularization of the gradient curvature across multiple tasks. GAT leverages two types of auxiliary tasks: self-supervised tasks, where the labels are generated automatically, and domain-knowledge tasks, where human experts provide additional labels. Experimentally, GAT increases the robust AUC of CheXpert medical imaging dataset from 50% to 83% and On CIFAR-10, GAT outperforms eight state-of-the-art adversarial training and achieves 56.21% robust accuracy with Resnet-50. Overall, we demonstrate that guided multi-task learning is an actionable and promising avenue to push further the boundaries of model robustness.
翻译:尽管利用额外训练数据已被证实能有效提升对抗鲁棒性,但这不可避免地增加了数据收集成本及模型训练的计算负担。为缓解这些成本,我们提出引导式对抗训练(GAT),一种在有限训练数据条件下利用辅助任务的新型对抗训练技术。该方法在对抗训练的极小-极大优化过程中将单任务模型扩展为多任务模型,并通过跨多任务的梯度曲率正则化驱动损失优化。GAT利用两类辅助任务:自监督任务(标签自动生成)和领域知识任务(人类专家提供额外标签)。实验表明,在CheXpert医学影像数据集上,GAT将鲁棒AUC从50%提升至83%;在CIFAR-10数据集上,GAT以ResNet-50架构超越八种当前最优对抗训练方法,达到56.21%的鲁棒准确率。总体而言,我们证明引导式多任务学习是进一步突破模型鲁棒性边界的一种可行且有前景的途径。