[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-124670-en":3,"doc-seo-124670-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},124670,962075006959,"Anda","https://ap-avatar.wpscdn.com/avatar/e0002397efbe92a78e?_k=1776741047341049297",8,"Research & Report","Improving Machine Learning Robustness via Adversarial Training","Machine learning robustness is essential when models are exposed to worst-case noise, adversarial attacks, and unusual conditions in real-world deployments. This work studies adversarial training in centralized and decentralized settings, covering cases where training and testing occur on one or multiple computers. In centralized learning, robust test accuracy is evaluated under FGSM and DeepFool and shows significant gains over prior results. In decentralized federated learning, robustness is analyzed for IID versus non-IID data using CIFAR-10, revealing accuracy degradation under non-IID settings and attacks, and an IID data-sharing approach that improves both natural and robust accuracy.","Improving Machine Learning Robustness via  \nAdversarial Training  \nLong Dang  \nICNS Lab and Cyber Florida University of South Florida Tampa, FL. USA[longdang@usf.edu](longdang@usf.edu)  \nThushari Hapuarachchi  \nICNS Lab and Cyber Florida University of South Florida Tampa, FL. USA [saumya2@usf.edu](saumya2@usf.edu)  \nKaiqi Xiong  \nICNS Lab and Cyber Florida University of South Florida Tampa, FL. USA [xiongk@usf.edu](xiongk@usf.edu)  \nJing Lin  \nICNS Lab and Cyber Florida University of South Florida Tampa, FL. USA [jinglin@usf.edu](jinglin@usf.edu)  \narXiv :2309 . 12593v1 [ cs .LG] 22 Sep 2023  \nAbstract—As Machine Learning (ML) is increasingly used in solving various tasks in real-world applications, it is crucial to ensure that ML algorithms are robust to any potential worst-case noises, adversarial attacks, and highly unusual situations when they are designed. Studying ML robustness will significantly help in the design of ML algorithms. In this paper, we investigate ML robustness using adversarial training in centralized and decentralized environments, where ML training and testing are conducted in one or multiple computers. In the centralized environment, we achieve a test accuracy of 65.41% and 83.0% when classifying adversarial examples generated by Fast Gradient Sign Method and DeepFool, respectively. Comparing to existing studies, these results demonstrate an improvement of 18.41% for FGSM and 47% for DeepFool. In the decentralized environment, we study Federated learning (FL) robustness by using adversarial training with independent and identically distributed (IID) and non-IID data, respectively, where CIFAR-10 is used in this research. In the IID data case, our experimental results demonstrate that we can achieve such a robust accuracy that it is comparable to the one obtained in the centralized environment. Moreover, in the non-IID data case, the natural accuracy drops from 66.23% to 57.82%, and the robust accuracy decreases by 25% and 23.4% in C&W and Projected Gradient Descent (PGD) attacks, compared to the IID data case, respectively. We further propose an IID data-sharing approach, which allows for increasing the natural accuracy to 85.04% and the robust accuracy from 57% to 72% in C&W attacks and from 59% to 67% in PGD attacks.  \nIndex Terms—Machine learning robustness, Adversarial training, Federated learning, Independent and identically distributed (IID) and non-IID data  \nI. INTRODUCTION  \nMachine Learning (ML) is increasingly used in solving various tasks in real-world applications, for example, image and speech recognition, traffic engineering and securing invehicle networks [1], malware detection [2] and security attack detection, identification of diseases and diagnosis, as well as drug discovery and manufacturing. It is crucial to ensure that ML algorithms are robust to any potential worst-case noises, adversarial attacks, and highly unusual situations when they are designed. The studies of ML robustness will greatly help in the design of ML algorithms to reduce or avoid the potentially risky use of ML in various real-world applications.  \nIn this research, we investigate ML robustness by using adversarial training in the centralized and decentralized environments, where ML training and testing are conducted in  \none or multiple computers, respectively. In the centralized environment, adversarial attacks (i.e., adversarial examples are introduced in the testing time, or minor noise is intentionally added to testing data) are to mislead a classifier’s prediction. Fig. 1 illustrates how adversarial examples are difficult tobe distinguished from natural images by an ML model, but they are easily recognized by human eyes [3] . Many defense strategies against adversarial examples have been proposed over the years. Among them, adversarial training is one of the most promising defense techniques against evasion attacks (or adversarial examples) [4]–[6] . Lin, et al. [3] introduced soft labeling in adversarial ","cbCaiqxxHZDuhXwz","https://ap.wps.com/l/cbCaiqxxHZDuhXwz","pdf",716651,1,10,"English","en",105,"# Introduction\n## Centralized adversarial training\n## Decentralized federated learning robustness","[{\"question\":\"What problem does the paper address?\",\"answer\":\"The paper addresses how to ensure machine learning models remain robust against worst-case noise and adversarial attacks in real-world conditions.\"},{\"question\":\"How does the study evaluate robustness in the centralized environment?\",\"answer\":\"It uses adversarial training and tests under adversarial examples generated by FGSM and DeepFool, reporting robust test accuracies and improvements over existing studies.\"},{\"question\":\"What impact does IID vs non-IID data have on federated learning robustness?\",\"answer\":\"The paper shows that with non-IID data, natural accuracy drops and robust accuracy decreases under C\\u0026W and PGD attacks compared with the IID case.\"}]","Improving Machine Learning Robustness via Adversarial Training | PDF",1785893829,25,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"improving-machine-learning-robustness-via-adversarial-training","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/improving-machine-learning-robustness-via-adversarial-training/124670/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the paper address?","Question",{"text":75,"@type":76},"The paper addresses how to ensure machine learning models remain robust against worst-case noise and adversarial attacks in real-world conditions.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the study evaluate robustness in the centralized environment?",{"text":80,"@type":76},"It uses adversarial training and tests under adversarial examples generated by FGSM and DeepFool, reporting robust test accuracies and improvements over existing studies.",{"name":82,"@type":73,"acceptedAnswer":83},"What impact does IID vs non-IID data have on federated learning robustness?",{"text":84,"@type":76},"The paper shows that with non-IID data, natural accuracy drops and robust accuracy decreases under C&W and PGD attacks compared with the IID case.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":21,"slug":133},"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]