Classifier Adversarial Training Using Pre-Generated Perturbations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Classifiers, especially those based on machine learning models, are susceptible to adversarial examples, and existing adversarial training methods require time-consuming adaptation of initial perturbations to become robust, which slows down the training process.

Innovation Solution

A method that provides diverse initial perturbations for adversarial training, allowing quick adjustment to training data, speeding up the training process and resulting in a more robust classifier by training with more data within a given timeframe.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If adversarial training methods are used to harden classifiers against adversarial examples, then the robustness of the classifier is improved, but the training time increases significantly due to the need to adapt initial perturbations to the training data

Engineering Contradiction:
Improverobustness of classifierVSAvoidtraining time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by providing a diverse set of pre-generated initial perturbations before the adversarial training process begins. These perturbations are prepared in advance and can be directly used or require only minimal adaptation to the training data, eliminating the time-consuming step of generating and adapting perturbations during training. This allows the classifier to immediately benefit from robustness training without the initial time investment.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If initial perturbations are adapted to training data to create strong adversarial examples, then the robustness of the classifier is improved, but the adaptation process takes a long time

Engineering Contradiction:
Improverobustness of classifierVSAvoidadaptation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent generates and provides a diverse set of initial perturbations in advance, before the adversarial training process begins. These pre-prepared perturbations can be directly applied to training data or require only minimal adaptation, eliminating the time-consuming adaptation process that would otherwise be necessary to create strong adversarial examples during training.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If more training data is processed to improve classifier robustness, then the quality of the classifier is improved, but the training duration increases

Engineering Contradiction:
Improvequality of classifierVSAvoidtraining duration
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

By providing diverse initial perturbations in advance, the patent enables the training process to immediately utilize more training data without the initial time investment required for perturbation generation and adaptation. This allows the classifier to be trained on a larger volume of data within the same time frame, improving robustness without extending training duration.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20210319315A1Device and method for training a classifier and assessing the robustness of a classifier
Publication Date: 2021.10.14 ROBERT BOSCH GMBH
  • US20210319315A1 patent drawing
  • US20210319315A1 patent drawing
  • US20210319315A1 patent drawing

AI summary

A computer-implemented method for training a classifier. The classifier is configured to classify input signals of digital image data and/or audio data. The training of the classifier is based on a perturbed input signal obtained by applying a perturbation provided from a plurality of perturbations to an input signal provided from a training dataset. The method includes: providing a plurality of initial perturbations; adapting a perturbation from the plurality of initial perturbations to an input signal, wherein the input signal is randomly drawn from the training dataset and the perturbation is adapted to the input signal such that applying the perturbation to the input signal yields a second input signal, which is classified differently than the first input signal; providing a subset of the plurality of initial perturbations as plurality of perturbations; and training the classifier based on the plurality of perturbations.