Global Wasserstein Margin Maximization for Boosting Generalization in Adversarial Training

Yu Tingyue,Wang Shen,Yu Xiangzhan
DOI: https://doi.org/10.1007/s10489-022-03480-w
IF: 5.3
2022-01-01
Applied Intelligence
Abstract:In recent researches on adversarial robustness boosting, the trade-off between standard and robust generalization has been widely concerned, in which margin, the average distance from samples to the decision boundary, has become the bridge between the two ends. In this paper, the problems of the existing methods to improve the adversarial robustness by maximizing the margin are discussed and analyzed. On this basis, a new method to approximate the margin from a global point of view through the Wasserstein Distance of distribution of representation is proposed, which is called Global Wasserstein Margin. By maximizing the Global Wasserstein Margin in the process of adversarial training, the generalization capability of the model can be improved, reflected as the standard and robust accuracy advantages on the latest baseline of adversarial training.
What problem does this paper attempt to address?