pith. sign in

arxiv: 1903.11626 · v2 · pith:4UMQCATPnew · submitted 2019-03-27 · 💻 cs.LG · cs.AI· stat.ML

Bridging Adversarial Robustness and Gradient Interpretability

classification 💻 cs.LG cs.AIstat.ML
keywords adversarialtraininggradientslossdnnsgradientinterpretabilityadversarially
0
0 comments X
read the original abstract

Adversarial training is a training scheme designed to counter adversarial attacks by augmenting the training dataset with adversarial examples. Surprisingly, several studies have observed that loss gradients from adversarially trained DNNs are visually more interpretable than those from standard DNNs. Although this phenomenon is interesting, there are only few works that have offered an explanation. In this paper, we attempted to bridge this gap between adversarial robustness and gradient interpretability. To this end, we identified that loss gradients from adversarially trained DNNs align better with human perception because adversarial training restricts gradients closer to the image manifold. We then demonstrated that adversarial training causes loss gradients to be quantitatively meaningful. Finally, we showed that under the adversarial training framework, there exists an empirical trade-off between test accuracy and loss gradient interpretability and proposed two potential approaches to resolving this trade-off.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.