Average Margin Regularization for Classifiers

Average Margin Regularization for Classifiers
复制标题

DOI:
10.1109/cdc42340.2020.9303984
复制
发表时间:
2018-10
期刊:
2020 59th IEEE Conference on Decision and Control (CDC)
影响因子:
--
通讯作者:
Matt Olfat;A. Aswani
Matt Olfat;A. Aswani
中科院分区:
其他
文献类型:
--
作者:
Matt Olfat;A. Aswani

文献摘要

相似文献

鉴于深度神经网络缺乏鲁棒性的实证证明,对抗鲁棒性已经成为一个重要的研究课题。不幸的是,最近的理论结果表明,对抗训练在分类准确性和对抗鲁棒性之间产生了严格的权衡。在本文中,我们提出并研究了一种新的正则化方法,用于任何边缘分类器或深度神经网络。我们激励这种正则化的一个新的泛化界,表现出在分类器的准确性之间的权衡最大化其利润率和平均利润率。因此,我们将我们的方法称为平均间隔(AM)正则化,它由添加到目标的线性项组成。我们从理论上证明,对于某些分布,AM正则化可以提高分类器的准确性和对抗性攻击的鲁棒性。我们得出结论,使用合成和真实的数据的经验表明,AM正则化可以严格提高支持向量机(SVM)的准确性和鲁棒性,相对于未正则化分类器和逆向训练分类器。
Adversarial robustness has become an important research topic given empirical demonstrations on the lack of robustness of deep neural networks. Unfortunately, recent theoretical results suggest that adversarial training induces a strict tradeoff between classification accuracy and adversarial robustness. In this paper, we propose and then study a new regularization for any margin classifier or deep neural network. We motivate this regularization by a novel generalization bound that shows a tradeoff in classifier accuracy between maximizing its margin and average margin. We thus call our approach an average margin (AM) regularization, and it consists of a linear term added to the objective. We theoretically show that for certain distributions AM regularization can both improve classifier accuracy and robustness to adversarial attacks. We conclude by using both synthetic and real data to empirically show that AM regularization can strictly improve both accuracy and robustness for support vector machine’s (SVM’s), relative to unregularized classifiers and adversarially trained classifiers.