Web: http://arxiv.org/abs/2204.12393

April 27, 2022, 1:20 a.m. | Nils Philipp Walter, David Stutz, Bernt Schiele

cs.CR updates on arXiv.org arxiv.org

Modern deep learning architecture utilize batch normalization (BN) to
stabilize training and improve accuracy. It has been shown that the BN layers
alone are surprisingly expressive. In the context of robustness against
adversarial examples, however, BN is argued to increase vulnerability. That is,
BN helps to learn fragile features. Nevertheless, BN is still used in
adversarial training, which is the de-facto standard to learn robust features.
In order to shed light on the role of BN in adversarial training, we …

adversarial batch features lg training

