Adversarial training with borderline samples
摘要
Convolutional Neural Networks (CNNs) have achieved tremendous success in image classification tasks. However, CNNs are vulnerable to adversarial attacks, such as applying imperceptible perturbations on the legitimate images. To address the security threats posed by these adversarial attacks, many defense techniques have been proposed. Adversarial training has been shown to be effective in enhancing CNNs robustness against adversarial samples. However, the trade-off between robustness and classification accuracy in adversarial training cannot be overlooked. In this paper, we propose a novel approach to adversarial training that simultaneously trains the model using both real images and minimally perturbed borderline adversaries. These borderline adversaries were generated during the training process, using the shortest successful perturbations for each individual training sample at specific training states. Instead of training with a fixed