SOTAVerified

Enhance the Visual Representation via Discrete Adversarial Training

2022-09-16Code Available0· sign in to hype

Xiaofeng Mao, Yuefeng Chen, Ranjie Duan, Yao Zhu, Gege Qi, Shaokai Ye, Xiaodan Li, Rong Zhang, Hui Xue

Code Available — Be the first to reproduce this paper.

Reproduce

Code

Abstract

Adversarial Training (AT), which is commonly accepted as one of the most effective approaches defending against adversarial examples, can largely harm the standard performance, thus has limited usefulness on industrial-scale production and applications. Surprisingly, this phenomenon is totally opposite in Natural Language Processing (NLP) task, where AT can even benefit for generalization. We notice the merit of AT in NLP tasks could derive from the discrete and symbolic input space. For borrowing the advantage from NLP-style AT, we propose Discrete Adversarial Training (DAT). DAT leverages VQGAN to reform the image data to discrete text-like inputs, i.e. visual words. Then it minimizes the maximal risk on such discrete images with symbolic adversarial perturbations. We further give an explanation from the perspective of distribution to demonstrate the effectiveness of DAT. As a plug-and-play technique for enhancing the visual representation, DAT achieves significant improvement on multiple tasks including image classification, object detection and self-supervised learning. Especially, the model pre-trained with Masked Auto-Encoding (MAE) and fine-tuned by our DAT without extra data can get 31.40 mCE on ImageNet-C and 32.77% top-1 accuracy on Stylized-ImageNet, building the new state-of-the-art. The code will be available at https://github.com/alibaba/easyrobust.

Tasks

Benchmark Results

DatasetModelMetricClaimedVerifiedStatus
ImageNet-AMAE+DAT (ViT-H)Top-1 accuracy %68.92Unverified
ImageNet-CMAE+DAT (ViT-H)mean Corruption Error (mCE)31.4Unverified
ImageNet-RMAE+DAT (ViT-H)Top-1 Error Rate34.39Unverified
ImageNet-SketchMAE+DAT (ViT-H)Top-1 accuracy50.03Unverified
Stylized ImageNetMAE+DAT (ViT-H)Top 1 Accuracy32.77Unverified

Reproductions