Page 145 - 《软件学报》2026年第4期
P. 145
1586 软件学报 2026 年第 37 卷第 4 期
表 6 在 PASCAL VOC 2007 测试集上对不同 K 值的 NAG ad 和 v LR 的消融研究
mAP (%)
算法 训练时间 (min)
干净样本 A cls A loc CWA
PGD-10 77.21 39.44 47.03 40.27 1 165
PGD-20 76.39 43.72 50.53 43.91 2 334
PGD-LR-10 76.58 48.54 51.12 50.38 1 167
PGD-LR-20 77.19 49.43 51.92 50.04 2 343
NAG adv -10 76.95 42.19 55.52 43.97 1 189
NAG adv -20 77.21 44.70 56.61 46.21 2 377
NAG adv -LR-10 77.10 41.55 55.27 42.99 1 195
NAG adv -LR-20 76.90 49.84 60.47 50.93 2 391
表 7 在 MS-COCO 2017 验证集上对不同 K 值的 NAG ad 和 v LR 的消融研究
mAP (%)
算法 训练时间 (min)
干净样本 A cls A loc CWA
PGD-10 40.64 1.85 8.09 2.35 2 186
PGD-20 40.50 6.96 11.88 7.52 4 378
PGD-LR-10 40.42 1.79 7.98 2.05 2 253
PGD-LR-20 40.68 11.05 13.71 11.18 4 517
NAG adv -10 40.48 13.46 20.81 15.23 2 189
NAG adv -20 40.46 16.50 22.24 17.48 4 510
NAG adv -LR-10 40.82 16.31 20.46 17.24 2 259
NAG adv -LR-20 40.35 15.34 20.23 16.56 4 525
4 总 结
本文提出了一种新的目标检测对抗训练方法, 通过引入 NAG 动量加快鲁棒优化内层最大化问题的收敛, 达
到加速对抗训练的效果. 另一方面, 在多任务损失函数的基础上, 巧妙设计了自适应权重对定位和分类损失进行重
加权, 实现了目标检测模型鲁棒性的提升. 本文的公式推导证明了所提方法与原始 NAG 的收敛速率相匹配, 从而
建立起优化理论与对抗鲁棒现实场景之间的深层联系, 这是一种极其有意义的尝试, 并且在实际中取得了比 PGD
更好的效果, 对进一步研究对抗鲁棒性的理论收敛具有启发式的意义. 此外, 希望通过本文的研究, 能够促进优化
领域中更多先进方法扩展到深度神经网络对抗训练, 尤其是应用在目标检测等计算机视觉核心任务中, 以提高模
型鲁棒性、降低计算开销.
References
[1] Biggio B, Corona I, Maiorca D, Nelson B, Šrndić N, Laskov P, Giacinto G, Roli F. Evasion attacks against machine learning at test time.
In: Proc. of the 2013 European Conf. on Machine Learning and Knowledge Discovery in Databases. Prague: Springer, 2013. 387–402.
[doi: 10.1007/978-3-642-40994-3_25]
[2] Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R. Intriguing properties of neural networks. In: Proc. of the
2014 Int’l Conf. on Learning Representations. OpenReview.net. 2014.
[3] Goodfellow IJ, Shlens J, Szegedy C. Explaining and harnessing adversarial examples. In: Proc. of the 2015 Int’l Conf. on Learning
Representations. 2015.
[4] Kurakin A, Goodfellow IJ, Bengio S. Adversarial machine learning at scale. In: Proc. of the 2017 Int’l Conf. on Learning
Representations. OpenReview.net. 2017.
[5] Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A. Towards deep learning models resistant to adversarial attacks. In: Proc. of the
2019 Int’l Conf. on Learning Representations. OpenReview.net. 2019.
[6] Tramèr F, Kurakin A, Papernot N, Goodfellow I, Boneh D, McDaniel P. Ensemble adversarial training: Attacks and defenses. In: Proc. of
the 2020 Int’l Conf. on Learning Representations. OpenReview.net. 2020.

