| 本文已被:浏览 1847次 下载 1364次 |
 码上扫一扫! |
|
|
| 基于自适应策略优化的鲁棒泛化权衡学习 |
|
翟浩杰1, 王冉2,3, 邬文慧4,3, 贾育衡5
|
|
1.深圳大学 数学科学学院, 广东 深圳 518060;2.深圳大学 人工智能学院, 广东 深圳 518060;3.广东省智能信息处理重点实验室(深圳大学), 广东 深圳 518060;4.深圳大学 电子与信息工程学院, 广东 深圳 518060;5.东南大学 计算机科学与工程学院, 江苏 南京 211189
|
|
| 摘要: |
| 对抗训练被视为提升深度模型鲁棒性的核心防御手段, 但其固有缺陷严重制约了实际应用效果. 传统对抗训练方法依赖固定攻击模式生成对抗样本, 导致训练过程中样本多样性不足、模型泛化能力受限, 且在鲁棒性与干净准确率间难以达成有效平衡. 更为关键的是, 现有对抗训练框架缺乏对训练过程的自适应控制, 容易引发鲁棒过拟合现象. 针对上述挑战, 利用演化优化提出一个自适应对抗训练框架, 称为基于自适应策略优化的鲁棒泛化权衡学习, 简称TRG-ASO. 该方法将遗传算法引入对抗训练过程, 通过动态调整不同训练阶段的对抗攻击策略, 实现对抗样本生成模式的渐进式复杂化. 这种层级递进的对抗机制不仅增强了样本多样性, 还可通过策略优化记录实现训练早停, 有效抑制过拟合风险. 在CIFAR系列数据集上的实验表明, 相较于传统对抗训练方法, 所提框架在维持基础分类性能的同时, 提升了模型面对多种攻击范式的防御能力, 且加快了训练收敛速度. 为对抗训练中鲁棒性-泛化性的权衡提供了新思路, 对构建可信深度学习系统具有重要实践价值. |
| 关键词: 鲁棒性 自适应策略优化 权衡学习 对抗训练 演化优化 |
| DOI:10.13328/j.cnki.jos.007522 |
| 分类号:TP18 |
| 基金项目:国家自然科学基金(62176160, U24A20322, 62376162); 广东省基础与应用基础研究基金自然科学基金(2024B1515020109); 广东省智能信息处理重点实验室(2023B1212060076) |
|
| Trade-off Learning for Robustness and Generalization Based on Adaptive Strategy Optimization |
|
ZHAI Hao-Jie1, WANG Ran2,3, WU Wen-Hui4,3, JIA Yu-Heng5
|
|
1.School of Mathematical Sciences, Shenzhen University, Shenzhen 518060, China;2.School of Artificial Intelligence, Shenzhen University, Shenzhen 518060, China;3.Guangdong Key Laboratory of Intelligent Information Processing (Shenzhen University), Shenzhen 518060, China;4.College of Electronic and Information Engineering, Shenzhen University, Shenzhen 518060, China;5.School of Computer Science and Engineering, Southeast University, Nanjing 211189, China
|
| Abstract: |
| Adversarial training is regarded as a core defense mechanism for enhancing the robustness of deep models, yet its inherent limitations significantly constrain its effectiveness in practical applications. Traditional adversarial training methods rely on fixed attack patterns to generate adversarial examples (AEs), leading to insufficient sample diversity, limited generalization capabilities, and difficulties in achieving an effective balance between robustness and clean accuracy. More crucially, existing adversarial training frameworks lack adaptive control over the training process, resulting in the robust overfitting phenomenon. To address these challenges, an evolutionary optimization-based adaptive adversarial training framework is proposed, named trade-off robustness and generalization via adaptive strategy optimization (TRG-ASO). It innovatively integrates a genetic algorithm into adversarial training and achieves progressive complexity escalation in AE generation through dynamic adjustment of attack strategies across different training phases. This mechanism not only enhances sample diversity but also effectively suppresses overfitting risks through early stopping enabled by strategy optimization records. Experiments on CIFAR series datasets demonstrate that, compared with traditional adversarial training methods, the proposed TRG-ASO framework maintains baseline classification performance while improving robustness against multiple attack paradigms and accelerating training convergence. This study provides new insights into the robustness-generalization trade-off in adversarial training, offering significant practical value for building trustworthy deep learning systems. |
| Key words: robustness adaptive strategy optimization trade-off learning adversarial training evolutionary optimization |