2020

Voting based ensemble improves robustness of defensive models

Devvrit, Cheng, Minhao, Hsieh, Cho-Jui et al.

Understand

Developing robust models against adversarial perturbations has been an active area of research and many algorithms have been proposed to train individual robust models.

  • Taking these pretrained robust models, we aim to study whether it is possible to create an ensemble to further improve robustness.
  • Several previous attempts tackled this problem by ensembling the soft-label prediction and have been proved vulnerable based on the latest attack methods.
  • In this paper, we show that if the robust training loss is diverse enough, a simple hard-label based voting ensemble can boost the robust error over each individual model.

Reading the bibliography…