Get Fooled for the Right Reason: Improving Adversarial Robustness through a Teacher-guided Curriculum Learning Approach
Current SOTA adversarially robust models are mostly based on adversarial\ntraining (AT) and differ only by some regularizers either at inner maximization\nor outer minimization steps. Being repetitive in nature during the inner\nmaximization step, they take a huge time to train. We propose a non-iterative\nmethod that enforces the following ideas during training. Attribution maps are\nmore aligned to the actual object in the image for adversarially robust models\ncompared to naturally trained models. Also, the allowed set of pixels to\nperturb an image (that changes model decision) should be restricted to the\nobject pixels only, which reduces the attack strength by limiting the attack\nspace. Our method achieves significant performance gains with a little extra\neffort (10-20%) over existing AT models and outperforms all other methods in\nterms of adversarial as well as natural accuracy. We have performed extensive\nexperimentation with CIFAR-10, CIFAR-100, and TinyImageNet datasets and\nreported results against many popular strong adversarial attacks to prove the\neffectiveness of our method.\n
Paper
References (33)
Scroll for more · 21 remaining