Adversarial training is an effective but time-consuming way to train robust deep neural networks that can withstand strong adversarial attacks. As a response to its inefficiency, we propose Dynamic Efficient Adversarial Training (DEAT), which gradually increases the adversarial iteration during training. We demonstrate that the gradient's magnitude correlates with the curvature of the trained model's loss landscape, allowing it to reflect the effect of adversarial training. Therefore, based on the magnitude of the gradient, we propose a general acceleration strategy, M+ acceleration, which enables an automatic and highly effective method of adjusting the training procedure. M+ acceleration is computationally efficient and easy to implement. It is suited for DEAT and compatible with the majority of existing adversarial training techniques. Extensive experiments have been done on CIFAR-10 and ImageNet datasets with various training environments. The results show that the proposed M+ acceleration significantly improves the training efficiency of existing adversarial training methods while achieving similar robustness performance. This demonstrates that the strategy is highly adaptive and offers a valuable solution for automatic adversarial training.
翻译:对抗训练是训练能够抵御强对抗攻击的鲁棒深度神经网络的有效但耗时的方法。针对其低效性问题,我们提出动态高效对抗训练(DEAT),该方法在训练过程中逐步增加对抗迭代次数。我们证明梯度幅值与训练模型损失景观的曲率相关,从而能够反映对抗训练的效果。因此,基于梯度幅值,我们提出一种通用加速策略M+加速,该策略能够以自动化且高效的方式调整训练流程。M+加速计算效率高且易于实现,既适用于DEAT,也与现有大多数对抗训练技术兼容。我们在CIFAR-10和ImageNet数据集上,结合多种训练环境进行了大量实验。结果表明,所提出的M+加速在保持相似鲁棒性能的同时,显著提升了现有对抗训练方法的训练效率。这证明了该策略具有高度自适应性,并为自动化对抗训练提供了有价值的解决方案。