AROID: Improving Adversarial Robustness Through Online Instance-Wise Data Augmentation

arXiv:2306.07197 · cs.CV, cs.AI, cs.LG · Submitted 2023-06-12 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.

Tom: I'm Tom, and with me are Jane, Lu, senior AI researcher at Tsinghua, Meng, lead engineer at a mysterious AI startup and Lalam, the in-house Large Language Model.

Jane: Today's paper: "AROID: Improving Adversarial Robustness Through Online Instance-Wise Data Augmentation".

Tom: Deep neural networks are highly vulnerable to adversarial examples, posing significant security and trustworthiness risks for applications built upon them.

Jane: First, who's behind it and why it matters.

Title and authors: Tom: So, we're talking about "AROID: Improving Adversarial Robustness Through Online Instance-Wise Data Augmentation," and the authors are Lin Li, Jianing Qiu, Michael Spratling, with contributing authors listed too. Jane It’s interesting how they framed the title because it points directly to what they are doing: using online instance-wise data augmentation to boost adversarial robustness.

Lu: The paper introduces this as a novel method specifically designed for robustness that automates the learning of data augmentation policies, which is a big step compared to just picking fixed augmentation pipelines. Meng Automating that policy search sounds computationally intensive, so I'm curious how they managed to make it feasible without just creating another massive bottleneck.

Lalam: It suggests that instead of manually setting up a sequence of augmentations, the system learns which ones to apply and with what strength for every single input sample during training.

Tom: That’s the core idea, Jane; it means we’re moving from static augmentation strategies to something dynamic that changes based on the specific data point and where we are in the adversarial training process. Jane It really shifts the focus from finding a single best augmentation pipeline to creating a learning mechanism for augmentations themselves.

Meng: If this system can dynamically adjust its strategy, it means we could potentially fine-tune the defense mechanism as it encounters new types of adversarial examples during training.

The paper's summary: Tom: Now, diving into the summary of "AROID: Improving Adversarial Robustness Through Online Instance-Wise Data Augmentation," they explain that deep neural networks are susceptible to adversarial examples, and while adversarial training is a strong defense, it suffers from robust overfitting which degrades robustness substantially. Jane They argue that data augmentation can help prevent this overfitting if it’s designed correctly for adversarial training.

Lu: The paper proposes AROID as the first automated data augmentation method specifically for robustness, and its key innovation lies in proposing a novel policy learning objective that includes Vulnerability, Affinity, and Diversity. Meng That combination of objectives sounds like they are trying to hit three different angles at once: making things hard to attack, making them hard for a baseline model to classify differently, and ensuring they explore a wide variety of augmentations.

Lalam: I see how that diversity objective is important; it suggests the system isn't stuck in one small set of augmentation tricks but actively explores a much broader space of possibilities.

Tom: That’s right, Jane; the Vulnerability measures how much the loss varies when you add an adversarial perturbation to the augmented data compared to the target model, while Affinity looks at how well it makes things harder for a pre-trained affinity model. Jane And then they have Diversity to keep things from getting too narrow in its choice of augmentation transforms.

Lu: The training mechanism is bi-level optimization, where the target model learns using adversarial training with augmentations sampled from the policy, and then the policy model itself is updated based on gradients optimizing for hardness and diversity.

The paper's improvements: Tom: Looking at the improvements suggested by AROID, they propose a bi-level optimization framework that updates the target model using adversarial training with augmentations sampled from a learned policy, while the policy model is updated using gradients derived from a combined loss function that optimizes for hardness and diversity. Jane This structure allows them to learn data augmentation policies online as the training progresses.

Meng: The paper highlights how this method dramatically reduces the computational cost associated with searching for these optimal augmentation policies compared to existing methods like IDBH, which is a significant practical advantage. Lu The authors show that AROID takes nine hours to optimize for CIFAR10/PRN18, whereas IDBH required four hundred twelve hours for the same task.

Lalam: That reduction in search time is huge because it means we don't have to waste so much time just figuring out which data transformations are most useful.

Tom: And in terms of runtime during actual training, they note that AROID adds about forty-three point six percent extra computation compared to baseline adversarial training when T equals eight and K equals five. Jane That’s still a manageable overhead if the resulting model robustness gains justify it, and they report a robustness gap of zero point nine one percent on CIFAR10/one hundred with WRN34-ten.

Lu: Furthermore, they show strong generalization capabilities across different adversarial training methods like PGD and TRADES, as well as out-of-distribution shifts on datasets like CIFAR10-C.

Conclusion: Tom: So, to wrap up the "AROID: Improving Adversarial Robustness Through Online Instance-Wise Data Augmentation" paper, they’ve presented a method that learns dynamic, instance-wise data augmentation policies using Vulnerability, Affinity, and Diversity objectives. Jane Essentially, it automates the search for augmentations tailored to improve adversarial robustness in an online manner.

Meng: The practical implication here is a more efficient way to build robust AI models without spending hours searching for the perfect augmentation setup. Lu And from a research standpoint, they’ve shown that this framework can be integrated with other robust training techniques like SWA and AWP, which is really interesting for future model development.

Lalam: I think the ability of an AI to continuously evolve its own data processing based on feedback about its vulnerability is a fundamental step toward creating truly adaptive and resilient AI systems.

Tom: Absolutely, it’s a method that significantly reduces robust overfitting and shows good generalization across different scenarios, which is what matters most for real applications. Jane It’s definitely worth keeping an eye on this work as we look toward more sophisticated defenses against adversarial attacks.

Department of Informatics, King’s College London · Department of Computing, Imperial College London · Department of Behavioural and Cognitive Sciences, University of Luxembourg

cs.CV, cs.AI, cs.LG

Submitted: 2023-06-12

Updated: 2024-08-14

Comments: published at the IJCV in press

Journal ref: International Journal of Computer Vision (IJCV), 133:929-50, 2024

DOI: 10.1007/s11263-024-02206-4

Code: https://github.com/TreeLLi/AROID

License: http://creativecommons.org/licenses/by/4.0/

Importance score: 89/100

The gist: Deep neural networks are highly vulnerable to adversarial examples, posing significant security and trustworthiness risks for applications built upon them.

Key concepts

Adversarial Examples
These are tiny, malicious changes made to an image that are imperceptible to humans but cause a deep neural network to misclassify the input. They exploit weaknesses in the network's decision-making process, posing a major security risk.
Adversarial Training (AT)
A defense technique where the model is trained on data that has been intentionally perturbed by adversarial examples. The goal is to make the model robust against these attacks, but standard AT often leads to 'robust overfitting,' where the model performs well on training data but poorly on new, unseen examples.
Online Instance-wise Data Augmentation Policy
This is the core innovation of AROID. Instead of using fixed augmentations, AROID uses a neural network policy to dynamically choose which specific augmentation (e.g., shear or color change) to apply to each individual data sample during training, adapting the augmentation strategy as training progresses.
Vulnerability Objective
One of AROID's learning goals is 'Vulnerability.' This measures how much the loss changes when an augmented data sample is subjected to an adversarial attack. By minimizing this variation, AROID learns augmentations that make the data harder for the target model to be fooled by perturbations.

Terminology

Summary

Deep neural networks are highly vulnerable to adversarial examples, posing significant security and trustworthiness risks for applications built upon them. This paper introduces AROID (Adversarial Robustness through Online Instance-wise Data Augmentation), a novel method that automatically learns online, instance-wise data augmentation policies to improve the robust generalization of adversarial training (AT). AROID is significant because it is the first automated DA method specifically designed for robustness, and it dramatically reduces the computational cost associated with policy search compared to existing methods like AutoAugment and IDBH.

The Core Problem and Motivation

Deep neural networks are vulnerable to infinitesimal yet highly malicious artificial perturbations known as adversarial examples. While adversarial training (AT) is an effective defense, it is prone to overfitting, which significantly degrades robustness—a phenomenon termed robust overfitting. Previous data augmentation (DA) methods often fail to improve AT because they are not specifically designed for the demands of AT. The authors hypothesize that different data samples and training stages demand different DAs, leading to the proposal of AROID as a bi-level optimization framework to automatically learn online, instance-wise DA policies.

Modeling the Online Instance-Wise Data Augmentation Policy

AROID employs a multi-head DNN-based policy model parameterized by θplc to map an input data sample (x) to a DA policy. This policy is defined as a sequence of pre-defined transformations applied with a strength determined by the output of the policy model. The policy model utilizes multiple parallel linear prediction heads, one for each type of DA transformation (flip, crop, color/shape, and dropout). The output of each head is converted into a multinomial distribution where each logit represents a pre-defined sub-policy—an augmentation operation associated with a strength/magnitude (e.g., ShearX, 0.1). A particular sequence of sub-policies is then selected based on the probabilities encoded in these four heads.

Novel Policy Learning Objectives

The policy model is trained using three novel objectives: Vulnerability, Affinity, and Diversity. These objectives are designed to learn data augmentations with strong diversity and appropriate hardness:

  1. Vulnerability measures the loss variation caused by adversarial perturbation on the augmented data w.r.t the target model:

  2. Affinity captures the loss variation caused by DA w.r.t a model θaf t (the affinity model), which is a model pre-trained on original data, encouraging augmentations that make data harder for this affinity model to classify:

  3. Diversity enforces a relaxed uniform distribution prior over the logits of the policy model, penalizing overly small and large probabilities to constrain the distribution to lie in a pre-defined range (l, u), thereby promoting exploration across a diverse spectrum of augmentation techniques.

Bi-Level Optimization and Training Mechanism

The entire training process is a bi-level optimization framework where the target and policy models are updated alternately in an online manner. The target model is optimized using AT with the augmentation sampled from the policy model:

arg min θtgt L(ρ(Φ(x; S(θplc(x))); θtgt); θtgt)

After every K updates of the target model, the policy model is updated using gradients derived from a combined loss function that optimizes for hardness and diversity:

arg min θplc − Ei∈BLhrd(xi) + β · Eh∈HLhdiv(x; θplc)

The gradients for the non-differentiable Hardness objective are estimated using the REINFORCE algorithm with a baseline trick to reduce variance. This process is repeated online, allowing the DA policies to evolve as training progresses, producing a more globally optimal DA policy.

Efficiency and Empirical Results

AROID demonstrates superior performance over all competitive DA methods and state-of-the-art AT methods across various model architectures and datasets. Crucially, it dramatically reduces the cost of policy search: AROID takes 9 hours to optimize for CIFAR10/PRN18, compared to 412 hours for IDBH. In online mode, AROID adds about 43.6% extra computation to baseline AT when T=8 and K=5, which is substantially less than the search costs of AutoAugment (5000 hours) and IDBH (412 hours). Furthermore, AROID-T (offline mode) shows that the cost is roughly the same as other DA methods. The results confirm that AROID significantly reduces robust overfitting, achieving a robustness gap of 0.91% on CIFAR10/100 with WRN34-10.

Generalization and Scalability

AROID exhibits strong generalization capabilities across various AT methods (PGD, TRADES, SCORE) and out-of-distribution shifts (CIFAR10-C). It is shown to be complementary to other robust training methods like SWA and AWP.

Improvements for AI systems

As a fastidious researcher, I have thoroughly analyzed the AROID paper. The core innovation lies in moving from heuristic, manually optimized Data Augmentation (DA) strategies (like IDBH or AutoAugment) to an automated, instance-wise policy learning framework driven by three synergistic objectives: Vulnerability, Affinity, and Diversity.

Here are the specific improvements I propose for AI systems based on this research:


  1. A new defense mechanism called the AROID system that learns a dynamic data augmentation policy tailored to each input sample and training stage of an Adversarial Training (AT) process.

  2. The system can dynamically adjust its internal data augmentation strategy (e.g., rotation, color jitter, cropping magnitude) during the AT loop based on real-time feedback about how sensitive the augmented samples are to adversarial attacks and how well they fit the target model's loss landscape.

  3. It will automatically discover and apply novel combinations of existing transformations that maximize both robustness (by increasing sample hardness) and diversity (by exploring a wider range of augmentations), overcoming the limitations of fixed, pre-defined augmentation pipelines like AutoAugment or IDBH.

  4. The system can be deployed in an online mode where the policy model is continuously updated alongside the target model, allowing it to adapt its DA strategy as the target network learns new vulnerabilities during training.

  5. It will significantly reduce the computational overhead associated with searching for optimal DA policies, achieving search times drastically lower than heuristic methods (e.g., reducing search from 5000 hours down to 9 hours for CIFAR10/PRN18).

  6. The system can be used to mitigate robust overfitting, which is the tendency of AT methods to become overly specialized and lose generalization robustness, leading to a superior trade-off between accuracy and adversarial robustness across various model architectures (CNNs and ViTs).

  7. It can be integrated with other advanced AT methods (like TRADES or SWA) by using the sampled DA policy as an input prior, further boosting overall system resilience.

  8. The resulting AI models will exhibit superior generalization to Out-Of-Distribution (OOD) data shifts and common visual corruptions, as evidenced by its strong performance on datasets like CIFAR10-C.

Abstract

Deep neural networks are vulnerable to adversarial examples. Adversarial training (AT) is an effective defense against adversarial examples. However, AT is prone to overfitting which degrades robustness substantially. Recently, data augmentation (DA) was shown to be effective in mitigating robust overfitting if appropriately designed and optimized for AT. This work proposes a new method to automatically learn online, instance-wise, DA policies to improve robust generalization for AT. This is the first automated DA method specific for robustness. A novel policy learning objective, consisting of Vulnerability, Affinity and Diversity, is proposed and shown to be sufficiently effective and efficient to be practical for automatic DA generation during AT. Importantly, our method dramatically reduces the cost of policy search from the 5000 hours of AutoAugment and the 412 hours of IDBH to 9 hours, making automated DA more practical to use for adversarial robustness. This allows our method to efficiently explore a large search space for a more effective DA policy and evolve the policy as training progresses. Empirically, our method is shown to outperform all competitive DA methods across various model architectures and datasets. Our DA policy reinforced vanilla AT to surpass several state-of-the-art AT methods regarding both accuracy and robustness. It can also be combined with those advanced AT methods to further boost robustness. Code and pre-trained models are available at https://github.com/TreeLLi/AROID.

Sources

Related papers