2024
On the Duality Between Sharpness-Aware Minimization and Adversarial Training
ICML 2024poster
Adversarial Training (AT), which adversarially perturb the input samples during training, has been acknowledged as one of the most effective defenses against adversarial attacks, yet suffers from inevitably decreased clean accuracy. Instead of perturbing the samples, Sharpness-Aware Minimization (SA…