Recent studies show that models trained by continual learning can achieve the comparable performances as the standard supervised learning and the learning flexibility of continual learning models enables their wide applications in the real world. Deep learning models, however, are shown to be vulnerable to adversarial attacks. Though there are many studies on the model robustness in the context of standard supervised learning, protecting continual learning from adversarial attacks has not yet been investigated. To fill in this research gap, we are the first to study adversarial robustness in continual learning and propose a novel method called \textbf{T}ask-\textbf{A}ware \textbf{B}oundary \textbf{A}ugmentation (TABA) to boost the robustness of continual learning models. With extensive experiments on CIFAR-10 and CIFAR-100, we show the efficacy of adversarial training and TABA in defending adversarial attacks.
翻译:近期研究表明,通过持续学习训练的模型能够达到与标准监督学习相当的性能,且持续学习模型的学习灵活性使其在现实世界中具有广泛应用。然而,深度学习模型已被证明易受对抗攻击。尽管在标准监督学习背景下已有大量关于模型鲁棒性的研究,但如何保护持续学习免受对抗攻击尚未得到探究。为填补这一研究空白,我们率先研究持续学习中的对抗鲁棒性,并提出一种名为**任务感知边界增强**(TABA)的新方法,以提升持续学习模型的鲁棒性。通过在CIFAR-10和CIFAR-100上的大量实验,我们展示了对抗训练与TABA在防御对抗攻击方面的有效性。