Built independently by an author, for readers. Read the story and support ChapterPal

keyword

adversarial weight perturbations

Adversarial weight perturbations are calculated changes applied directly to the internal parameters of a machine learning model to maximize its loss or induce specific behavioral changes. In model training and robust optimization, these worst-case parameter shifts are systematically injected during learning to guide optimization toward flatter regions of the loss landscape, which helps reduce generalization error and improves resilience against variations. In security contexts, adversarial weight perturbations can also describe deliberate parameter modifications engineered to manipulate model decisions, degrade performance, or embed hidden backdoors into a trained network.

2 items

Efficient Sharpness-aware Minimization for Improved Training of Neural Networks

Efficient Sharpness-aware Minimization for Improved Training of Neural Networks

Jiawei Du, Hanshu Yan, Jiashi Feng, Joey Tianyi Zhou, Liangli Zhen, Rick Siow Mong Goh, Vincent Y. F. Tan

Why you should read this

Proposes Efficient Sharpness-Aware Minimizer (ESAM), an optimization technique that reduces the computational overhead of SAM from roughly 100% to 40% over base optimizers via stochastic weight perturbation and sharpness-sensitive data selection without sacrificing generalization accuracy.

Overparametrized Deep Neural Networks (DNNs) often achieve astounding performances, but may potentially result in severe generalization error. Recently, the relation between the sharpness of the loss landscape and the generalization error has been established by Foret et al. (2020), in which the Sharpness Aware Minimizer (SAM) was proposed to mitigate the degradation of the generalization. Unfortunately, SAM s computational cost is roughly double that of base optimizers, such as Stochastic Gradient Descent (SGD). This paper thus proposes Efficient Sharpness Aware Minimizer (ESAM), which boosts SAM s efficiency at no cost to its generalization performance. ESAM includes two novel and efficient training strategies-StochasticWeight Perturbation and Sharpness-Sensitive Data Selection. In the former, the sharpness measure is approximated by perturbing a stochastically chosen set of weights in each iteration; in the latter, the SAM loss is optimized using only a judiciously selected subset of data that is sensitive to the sharpness. We provide theoretical explanations as to why these strategies perform well. We also show, via extensive experiments on the CIFAR and ImageNet datasets, that ESAM enhances the efficiency over SAM from requiring 100% extra computations to 40% vis-a-vis base optimizers, while test accuracies are preserved or even improved.

Added

2026-10-05