Quantifying the Preferential Direction of the Model Gradient in Adversarial Training With Projected Gradient Descent
Lanfredi, Ricardo Bigolin, Schroeder, Joyce D., Tasdizen, Tolga
Adversarial training, especially projected gradient descent (PGD), has been the most successful approach for improving robustness against adversarial attacks. After adversarial training, gradients of models with respect to their inputs are meaningful and interpretable by humans. However, the concept of interpretability is not mathematically well established, making it difficult to evaluate it quantitatively. We define interpretability as the alignment of the model gradient with the vector pointing toward the closest point of the support of the other class. We propose a method for measuring this alignment for binary classification problems, using generative adversarial model training to produce the smallest residual needed to change the class present in the image. We show that PGD-trained models are more interpretable than the baseline according to our definition, and our metric presents higher alignment values than a competing metric formulation. We also show that enforcing this alignment increases the robustness of models without adversarial training.
Sep-10-2020
- Country:
- North America
- United States
- Utah > Salt Lake County
- Salt Lake City (0.04)
- Texas > Dallas County
- Dallas (0.04)
- New Jersey > Atlantic County
- Atlantic City (0.04)
- Nevada > Clark County
- Las Vegas (0.04)
- Louisiana > Orleans Parish
- New Orleans (0.04)
- California
- Los Angeles County > Long Beach (0.14)
- San Diego County > San Diego (0.04)
- Utah > Salt Lake County
- Canada
- Quebec > Montreal (0.04)
- British Columbia > Metro Vancouver Regional District
- Vancouver (0.05)
- United States
- Europe
- Asia > China
- Guangdong Province > Shenzhen (0.04)
- Africa > Ethiopia
- Addis Ababa > Addis Ababa (0.04)
- North America
- Genre:
- Research Report (0.83)
- Industry:
- Technology: