Pith. sign in

REVIEW 1 cited by

Improving Adversarial Robustness via Promoting Ensemble Diversity

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1901.08846 v3 pith:JOYRK35M submitted 2019-01-25 cs.LG stat.ML

classification cs.LGstat.ML
keywords ensembleadversarialdiversityindividualnetworksrobustnessmethodexamples
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Though deep neural networks have achieved significant progress on various tasks, often enhanced by model ensemble, existing high-performance models can be vulnerable to adversarial attacks. Many efforts have been devoted to enhancing the robustness of individual networks and then constructing a straightforward ensemble, e.g., by directly averaging the outputs, which ignores the interaction among networks. This paper presents a new method that explores the interaction among individual networks to improve robustness for ensemble models. Technically, we define a new notion of ensemble diversity in the adversarial setting as the diversity among non-maximal predictions of individual members, and present an adaptive diversity promoting (ADP) regularizer to encourage the diversity, which leads to globally better robustness for the ensemble by making adversarial examples difficult to transfer among individual members. Our method is computationally efficient and compatible with the defense methods acting on individual networks. Empirical results on various datasets verify that our method can improve adversarial robustness while maintaining state-of-the-art accuracy on normal examples.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Towards Adversarially Robust Deep Metric Learning

    cs.LG 2025-01 conditional novelty 4.0 of 10

    Ensemble Adversarial Training with data-split diversity improves PGD robustness for deep metric learning models over adapted classification defenses, but the evaluation has important gaps.

Pith tools