arXiv · 2106.06917
ATRAS: Adversarially Trained Robust Architecture Search
Abstract
In this paper, we explore the effect of architecture completeness on adversarial robustness. We train models with different architectures on CIFAR-10 and MNIST dataset. For each model, we vary different number of layers and different number of nodes in the layer. For every architecture candidate, we use Fast Gradient Sign Method (FGSM) to generate untargeted adversarial attacks and use adversarial training to defend against those attacks. For each architecture candidate, we report pre-attack, post-attack and post-defense accuracy for the model as well as the architecture parameters and the impact of completeness to the model accuracies.
Explore related subjects
Keep this discovery
Yigit Alparslan, Edward Kim. 2021-06-13. ATRAS: Adversarially Trained Robust Architecture Search. https://arxiv.org/abs/2106.06917
Cite the original work for its findings. Save a collection to share your selection of sources.