Synergy-of-Experts: Collaborate to Improve Adversarial Robustness
Synergy-of-Experts: Collaborate to Improve Adversarial Robustness
复制标题
DOI:
--
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Sen Cui;Jingfeng Zhang;Jian Liang;Bo Han;Masashi Sugiyama;Changshui Zhang
中科院分区:
文献类型:
--
作者:
Sen Cui;Jingfeng Zhang;Jian Liang;Bo Han;Masashi Sugiyama;Changshui Zhang
Learning adversarially robust models requires invariant predictions to a small neighborhood of its natural inputs, often encountering insufficient model capacity . There is research showing that learning multiple sub-models in an ensemble could mitigate this insufficiency, further improving the generalization and the robustness. However, the ensemble’s voting-based strategy excludes the possibility that the true predictions remain with the minority . Therefore, this paper further improves the ensemble through a collaboration scheme—Synergy-of-Experts (SoE). Compared with the voting-based strategy, the SoE enables the possibility of correct predictions even if there exists a single correct sub-model. In SoE, every sub-model fits its specific vulnerability area and reserves the rest of the sub-models to fit other vulnerability areas, which effectively optimizes the utilization of the model capacity. Empirical experiments verify that SoE outperforms various ensemble methods against white-box and transfer-based adversarial attacks. The source codes are available at https://github.com/cuis15/synergy-of-experts .