Neural Architecture Search for Wide Spectrum Adversarial Robustness
DOI:
https://doi.org/10.1609/aaai.v37i1.25118Keywords:
CV: Adversarial Attacks & Robustness, ML: Deep Neural Architectures, ML: OptimizationAbstract
One major limitation of CNNs is that they are vulnerable to adversarial attacks. Currently, adversarial robustness in neural networks is commonly optimized with respect to a small pre-selected adversarial noise strength, causing them to have potentially limited performance when under attack by larger adversarial noises in real-world scenarios. In this research, we aim to find Neural Architectures that have improved robustness on a wide range of adversarial noise strengths through Neural Architecture Search. In detail, we propose a lightweight Adversarial Noise Estimator to reduce the high cost of generating adversarial noise with respect to different strengths. Besides, we construct an Efficient Wide Spectrum Searcher to reduce the cost of adjusting network architecture with the large adversarial validation set during the search. With the two components proposed, the number of adversarial noise strengths searched can be increased significantly while having a limited increase in search time. Extensive experiments on benchmark datasets such as CIFAR and ImageNet demonstrate that with a significantly richer search signal in robustness, our method can find architectures with improved overall robustness while having a limited impact on natural accuracy and around 40% reduction in search time compared with the naive approach of searching. Codes available at: https://github.com/zhicheng2T0/Wsr-NAS.gitDownloads
Published
2023-06-26
How to Cite
Cheng, Z., Li, Y., Dong, M., Su, X., You, S., & Xu, C. (2023). Neural Architecture Search for Wide Spectrum Adversarial Robustness. Proceedings of the AAAI Conference on Artificial Intelligence, 37(1), 442-451. https://doi.org/10.1609/aaai.v37i1.25118
Issue
Section
AAAI Technical Track on Computer Vision I