2018

Robustness via curvature regularization, and vice versa

Moosavi-Dezfooli, Seyed-Mohsen, Fawzi, Alhussein, Uesato, Jonathan et al.

Understand

State-of-the-art classifiers have been shown to be largely vulnerable to adversarial perturbations.

  • One of the most effective strategies to improve robustness is adversarial training.
  • In this paper, we investigate the effect of adversarial training on the geometry of the classification landscape and decision boundaries.
  • We show in particular that adversarial training leads to a significant decrease in the curvature of the loss surface with respect to inputs, leading to a drastically more "linear" behaviour of the network.

Reading the bibliography…