Rethinking data augmentation for adversarial robustness

Pintor, Maura;Biggio, Battista;
2024-01-01

Abstract

Recent work has proposed novel data augmentation methods to improve the adversarial robustness of deep neural networks. In this paper, we re-evaluate such methods through the lens of different metrics that characterize the augmented manifold, finding contradictory evidence. Our extensive empirical analysis involving 5 data augmentation methods, all tested with an increasing probability of augmentation, shows that: (i) novel data augmentation methods proposed to improve adversarial robustness only improve it when combined with classical augmentations (like image flipping and rotation), and even worsen adversarial robustness if used in isolation; and (ii) adversarial robustness is significantly affected by the augmentation probability, conversely to what is claimed in recent work. We conclude by discussing how to rethink the development and evaluation of novel data augmentation methods for adversarial robustness. Our open-source code is available at https://github.com/eghbalz/rethink_da_for_ar
2024
2023
Inglese
654
119838
Esperti anonimi
scientifica
Eghbal-zadeh, Hamid; Zellinger, Werner; Pintor, Maura; Grosse, Kathrin; Koutini, Khaled; Moser, Bernhard A.; Biggio, Battista; Widmer, Gerhard ...espandi
1.1 Articolo in rivista
info:eu-repo/semantics/article
1 Contributo su Rivista::1.1 Articolo in rivista
262
8
partially_open
Files in This Item:
File Size Format  
1-s2.0-S0020025523014238-main.pdf

Solo gestori archivio

Type: versione editoriale
Size 1.74 MB
Format Adobe PDF
1.74 MB Adobe PDF & nbsp; View / Open   Request a copy
_INS__Rethinking_Data_Augmentation-3.pdf

open access

Type: versione pre-print
Size 1.55 MB
Format Adobe PDF
1.55 MB Adobe PDF View/Open

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

Questionnaire and social

Share on:
Impostazioni cookie