One popular hypothesis of neural network generalization is that the flat minima of loss surface in parameter space leads to good generalization., we demonstrate that loss surface in parameter space has no obvious with generalization, especially under adversarial settings. visualizing decision surfaces in both parameter space and input space, instead show that the geometry property of decision surface in input space well with the adversarial robustness. We then propose an adversarial indicator, which can evaluate a neural network's intrinsic property without testing its accuracy under adversarial attacks. by it, we further propose our robust training method. Without involving training, our method could enhance network's intrinsic adversarial against various adversarial attacks.
No takes yet. Share an insight, caveat, or question.
Yu et al. (2018) studied this question.