Adversarial training is a widely adopted defense technique that demonstrates strong robustness against adversarial attacks. However, its high computational cost hinders its scalability to large datasets and complex models. Fast Adversarial Training (FAT) addresses this issue by reducing training time, but often suffers from Catastrophic Overfitting (CO), leading to poor robustness. To overcome this limitation, we propose RLCAS, an adaptive step size strategy guided by regularization loss feedback. RLCAS dynamically adjusts the adversarial step size based on real-time loss variation, stabilizing training and mitigating CO. Extensive experiments across three benchmark datasets and multiple network architectures show that RLCAS consistently improves robustness over baseline methods and effectively defends against diverse attack strategies. Moreover, it achieves higher computational efficiency compared to multi-step adversarial training approaches. Overall, RLCAS offers a practical and effective enhancement to FAT, balancing robustness and efficiency in adversarial training.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing Fast Adversarial Training via RLCAS: Regularization Loss Feedback Constraints Adaptive Step Size

  • Chunlong Fan,
  • Chengyue Yu,
  • Li Xu

摘要

Adversarial training is a widely adopted defense technique that demonstrates strong robustness against adversarial attacks. However, its high computational cost hinders its scalability to large datasets and complex models. Fast Adversarial Training (FAT) addresses this issue by reducing training time, but often suffers from Catastrophic Overfitting (CO), leading to poor robustness. To overcome this limitation, we propose RLCAS, an adaptive step size strategy guided by regularization loss feedback. RLCAS dynamically adjusts the adversarial step size based on real-time loss variation, stabilizing training and mitigating CO. Extensive experiments across three benchmark datasets and multiple network architectures show that RLCAS consistently improves robustness over baseline methods and effectively defends against diverse attack strategies. Moreover, it achieves higher computational efficiency compared to multi-step adversarial training approaches. Overall, RLCAS offers a practical and effective enhancement to FAT, balancing robustness and efficiency in adversarial training.