Despite their performance, Artificial Neural Networks are not reliable enough\nfor most of industrial applications. They are sensitive to noises, rotations,\nblurs and adversarial examples. There is a need to build defenses that protect\nagainst a wide range of perturbations, covering the most traditional common\ncorruptions and adversarial examples. We propose a new data augmentation\nstrategy called M-TLAT and designed to address robustness in a broad sense. Our\napproach combines the Mixup augmentation and a new adversarial training\nalgorithm called Targeted Labeling Adversarial Training (TLAT). The idea of\nTLAT is to interpolate the target labels of adversarial examples with the\nground-truth labels. We show that M-TLAT can increase the robustness of image\nclassifiers towards nineteen common corruptions and five adversarial attacks,\nwithout reducing the accuracy on clean samples.\n
Paper
References (60)
Scroll for more · 38 remaining