SOTAVerified

Adversarial Training Generalizes Data-dependent Spectral Norm Regularization

2019-09-25Unverified0· sign in to hype

Kevin Roth, Yannic Kilcher, Thomas Hofmann

Unverified — Be the first to reproduce this paper.

Reproduce

Abstract

We establish a theoretical link between adversarial training and operator norm regularization for deep neural networks. Specifically, we present a data-dependent variant of spectral norm regularization and prove that it is equivalent to adversarial training based on a specific _2-norm constrained projected gradient ascent attack. This fundamental connection confirms the long-standing argument that a network's sensitivity to adversarial examples is tied to its spectral properties and hints at novel ways to robustify and defend against adversarial attacks. We provide extensive empirical evidence to support our theoretical results.

Tasks

Reproductions