Fantastic Robustness Measures: The Secrets of Robust Generalization
–Neural Information Processing Systems
Adversarial training has become the de-facto standard method for improving the robustness of models against adversarial examples. However, robust overfitting remains a significant challenge, leading to a large gap between the robustness on the training and test datasets. To understand and improve robust generalization, various measures have been developed, including margin, smoothness, and flatness-based measures. In this study, we present a large-scale analysis of robust generalization to empirically verify whether the relationship between these measures and robust generalization remains valid in diverse settings.
Neural Information Processing Systems
Feb-11-2025, 05:58:12 GMT