• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

对抗训练的数据依赖稳定性分析

Data-dependent stability analysis of adversarial training.

作者信息

Wang Yihan, Liu Shuang, Gao Xiao-Shan

机构信息

Academy of Mathematics and Systems Science, Chinese Academy of Sciences, Beijing, 100190, China; University of Chinese Academy of Sciences, Beijing, 101408, China.

Academy of Mathematics and Systems Science, Chinese Academy of Sciences, Beijing, 100190, China; University of Chinese Academy of Sciences, Beijing, 101408, China.

出版信息

Neural Netw. 2025 Mar;183:106983. doi: 10.1016/j.neunet.2024.106983. Epub 2024 Dec 4.

DOI:10.1016/j.neunet.2024.106983
PMID:39644596
Abstract

Stability analysis is an essential aspect of studying the generalization ability of deep learning, as it involves deriving generalization bounds for stochastic gradient descent-based training algorithms. Adversarial training is the most widely used defense against adversarial attacks. However, previous generalization bounds for adversarial training have not included information regarding data distribution. In this paper, we fill this gap by providing generalization bounds for stochastic gradient descent-based adversarial training that incorporate data distribution information. We utilize the concepts of on-average stability and high-order approximate Lipschitz conditions to examine how changes in data distribution and adversarial budget can affect robust generalization gaps. Our derived generalization bounds for both convex and non-convex losses are at least as good as the uniform stability-based counterparts which do not include data distribution information. Furthermore, our findings demonstrate how distribution shifts from data poisoning attacks can impact robust generalization.

摘要

稳定性分析是研究深度学习泛化能力的一个重要方面,因为它涉及为基于随机梯度下降的训练算法推导泛化界。对抗训练是抵御对抗攻击最广泛使用的防御方法。然而,先前对抗训练的泛化界并未包含有关数据分布的信息。在本文中,我们通过为基于随机梯度下降的对抗训练提供包含数据分布信息的泛化界来填补这一空白。我们利用平均稳定性和高阶近似利普希茨条件的概念来研究数据分布和对抗预算的变化如何影响鲁棒泛化差距。我们为凸损失和非凸损失推导的泛化界至少与不包含数据分布信息的基于均匀稳定性的对应界一样好。此外,我们的研究结果表明数据中毒攻击导致的分布偏移如何影响鲁棒泛化。

相似文献

1
Data-dependent stability analysis of adversarial training.对抗训练的数据依赖稳定性分析
Neural Netw. 2025 Mar;183:106983. doi: 10.1016/j.neunet.2024.106983. Epub 2024 Dec 4.
2
Stability analysis of stochastic gradient descent for homogeneous neural networks and linear classifiers.随机梯度下降在同质神经网络和线性分类器中的稳定性分析。
Neural Netw. 2023 Jul;164:382-394. doi: 10.1016/j.neunet.2023.04.028. Epub 2023 Apr 25.
3
Generalization analysis of adversarial pairwise learning.
Neural Netw. 2025 Mar;183:106955. doi: 10.1016/j.neunet.2024.106955. Epub 2024 Nov 28.
4
Perturbation diversity certificates robust generalization.摄动多样性证书保证了强健的泛化能力。
Neural Netw. 2024 Apr;172:106117. doi: 10.1016/j.neunet.2024.106117. Epub 2024 Jan 8.
5
Auto encoder-based defense mechanism against popular adversarial attacks in deep learning.基于自动编码器的深度学习中流行对抗攻击防御机制。
PLoS One. 2024 Oct 21;19(10):e0307363. doi: 10.1371/journal.pone.0307363. eCollection 2024.
6
Decentralized stochastic sharpness-aware minimization algorithm.去中心化随机锐化感知最小化算法。
Neural Netw. 2024 Aug;176:106325. doi: 10.1016/j.neunet.2024.106325. Epub 2024 Apr 17.
7
A fast saddle-point dynamical system approach to robust deep learning.一种快速鞍点动力学系统方法,用于鲁棒深度学习。
Neural Netw. 2021 Jul;139:33-44. doi: 10.1016/j.neunet.2021.02.021. Epub 2021 Feb 26.
8
Enhancing robustness in video recognition models: Sparse adversarial attacks and beyond.增强视频识别模型的鲁棒性:稀疏对抗攻击及其他。
Neural Netw. 2024 Mar;171:127-143. doi: 10.1016/j.neunet.2023.11.056. Epub 2023 Nov 25.
9
Between-Class Adversarial Training for Improving Adversarial Robustness of Image Classification.基于类间对抗训练提高图像分类对抗鲁棒性。
Sensors (Basel). 2023 Mar 20;23(6):3252. doi: 10.3390/s23063252.
10
Adversarial and Random Transformations for Robust Domain Adaptation and Generalization.对抗和随机变换在鲁棒域自适应和泛化中的应用。
Sensors (Basel). 2023 Jun 1;23(11):5273. doi: 10.3390/s23115273.