| 注册
首页|期刊导航|信息工程大学学报|元微调对抗训练:面向多类型对抗攻击的对抗训练改进方法

元微调对抗训练:面向多类型对抗攻击的对抗训练改进方法

刘文钊 杨奎武 陈越 郭靖臣 胡学先

信息工程大学学报2025,Vol.26Issue(4):470-477,8.
信息工程大学学报2025,Vol.26Issue(4):470-477,8.DOI:10.3969/j.issn.1671-0673.2025.04.014

元微调对抗训练:面向多类型对抗攻击的对抗训练改进方法

Meta Fine-Tuning Adversarial Training:An Improved Adversarial Training Approach for Multiple Types of Adversarial Attacks

刘文钊 1杨奎武 2陈越 2郭靖臣 2胡学先2

作者信息

  • 1. 信息工程大学,河南 郑州 450001||电子信息系统复杂电磁环境效应国家重点实验室,河南 洛阳 471003
  • 2. 信息工程大学,河南 郑州 450001
  • 折叠

摘要

Abstract

Adversarial training,as an important technique for enhancing model robustness,faces prob-lems of high training costs and inability to defend against multiple adversarial attacks.An improved ad-versarial training approach based on meta-learning is proposed.By integrating pre-training fine-tuning and diffusion model data generation strategies,a dual-branch training architecture is designed.One branch is fine-tuned on an l∞ robust model to improve its l∞ robustness,and the other branch trains against composite adversarialattacks to enhance the model's defense capabilities against non-lp norm at-tacks.During training,the weights of both branches are fused through a mixed model and periodically reinitialized,enabling the final model to simultaneously resist both l∞ attacks and composite adver-sarial attacks.Experimental results show that the proposed approach maintains l∞ robustness while achieving superior defensive performance against composite adversarial attacks on the composite ad-versarial robustness benchmark(CARBEN).

关键词

对抗训练/组合对抗攻击/对抗鲁棒性/元学习

Key words

adversarial training/composite adversarial attack/adversarial robustness/meta-learning

分类

信息技术与安全科学

引用本文复制引用

刘文钊,杨奎武,陈越,郭靖臣,胡学先..元微调对抗训练:面向多类型对抗攻击的对抗训练改进方法[J].信息工程大学学报,2025,26(4):470-477,8.

基金项目

国家自然科学基金(62172433) (62172433)

信息工程大学学报

1671-0673

访问量0
|
下载量0
段落导航相关论文