Skip to main content
QUICK REVIEW

[论文解读] Robust GANs against Dishonest Adversaries

Zhi Xu, Chengtao Li|arXiv (Cornell University)|Feb 27, 2018
Adversarial Robustness in Machine Learning参考文献 50被引用 3
一句话总结

本文提出了一种基于判别器反馈中对抗性扰动的新鲁棒性概念,表明标准 GAN 对此类噪声高度敏感。该文推导了鲁棒性的理论条件,提出了一类受 WGAN 启发的新 GAN 家族,具有更高的稳定性并减少了正则化需求,并通过实证验证表明这些模型对内部反馈污染更具鲁棒性。

ABSTRACT

Robustness of deep learning models is a property that has recently gained increasing attention. We explore a notion of robustness for generative adversarial models that is pertinent to their internal interactive structure, and show that, perhaps surprisingly, the GAN in its original form is not robust. Our notion of robustness relies on a perturbed discriminator, or noisy, adversarial interference with its feedback. We explore, theoretically and empirically, the effect of model and training properties on this robustness. In particular, we show theoretical conditions for robustness that are supported by empirical evidence. We also test the effect of regularization. Our results suggest variations of GANs that are indeed more robust to noisy attacks and have more stable training behavior, requiring less regularization in general. Inspired by our theoretical results, we further extend our framework to obtain a class of models related to WGAN, with good empirical performance. Overall, our results suggest a new perspective on understanding and designing GAN models from the viewpoint of their internal robustness.

研究动机与目标

  • 形式化基于判别器反馈内部对抗性干扰的 GAN 新鲁棒性概念。
  • 识别 GAN 对此类扰动变得鲁棒的理论条件。
  • 通过实证验证修改后的 GAN 架构在噪声反馈下的鲁棒性。
  • 将该框架扩展为一类新型 WGAN 类模型,具有更好的训练稳定性和更低的正则化需求。

提出的方法

  • 引入一种受扰动的反馈机制,即生成器以一定概率接收来自判别器的污染信号。
  • 基于生成器在该类反馈扰动下的学习稳定性,定义鲁棒性准则。
  • 通过 Ĥ 中的严格递增、奇函数,推导确保鲁棒性的目标函数理论条件。
  • 提出一种使用 Ĥ 中的 f_D 和 f_G 的广义 GAN 框架,包含线性和 WGAN 类损失。
  • 在判别器目标中应用梯度惩罚(类似 WGAN-GP),以强制实现-Lipschitz连续性。
  • 采用标准训练流程,使用 Adam 优化器并保持与 WGAN-GP 相同的超参数,以实现公平的实证比较。

实验结果

研究问题

  • RQ1原始 GAN 架构对判别器反馈信号中的小规模、对抗性扰动是否具有鲁棒性?
  • RQ2目标函数在何种理论条件下可确保 GAN 对内部反馈污染具有鲁棒性?
  • RQ3能否利用理论鲁棒性条件设计出训练稳定性更优的新 GAN 架构?
  • RQ4基于鲁棒框架设计的模型是否比标准 GAN 需要更少的正则化?
  • RQ5在训练稳定性和性能方面,所提出的鲁棒 GAN 与 WGAN-GP 和标准 GAN 相比如何?

主要发现

  • 原始 GAN 对判别器反馈中的微小扰动并不鲁棒,导致在许多情况下训练失败。
  • 使用线性或 WGAN 类损失的模型——特别是 f_D 和 f_G 属于 Ĥ 的模型——在理论上和实证上对反馈噪声更具鲁棒性。
  • 所提出的鲁棒 GAN 框架在显著减少正则化需求的情况下实现了稳定训练,优于标准 GAN。
  • 实证结果表明,所提模型在生成多样化数字(如 MNIST)方面成功率更高,且无模式崩溃现象。
  • 在框架中加入梯度惩罚可保持稳定性并提升性能,Inception 分数随训练迭代稳步提升。
  • 该框架可无缝集成至现有 WGAN-GP 实现中,仅需极少代码修改。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。