Jen-Tzung Chien, Mahdin Rohmatillah, Chang-Ting Chu
Adversarial data augmentation techniques have recently demonstrated potential in enhancing the robustness of machine learning models by identifying potential worst-case data augmentation. However, most of the existing methods implemented a single augmentation strategy for different instances through a process of greedy search, resulting in suboptimal quality of the generated data. Furthermore, previous studies that incorporated reinforcement learning (RL) to apply unique augmentation strategies required high computational cost, as it necessitated a child network to compute the reward during the optimization process. Given these limitations, this study introduces a strategic adversarial data augmentation approach that leverages RL to search for and emulate the worst-case variations through a sequence of augmentation actions. By defining a reward function with an information-theoretic perspective along with the proper definition of state space, a proficient strategy for stacking multiple augmentation strategies can be carried out in an inexpensive way and can be smoothly integrated into classifier training, thereby enhancing model robustness against unseen noises. The proposed adversarial training method was evaluated on ten different types of unseen human-readable noises across six distinct text classification tasks. Experimental results indicate that the proposed method significantly improves model robustness in compensating for unseen noises. © 2014 IEEE.
National Yang Ming Chiao Tung University, Institute Of Electrical And Computer Engineering, Taiwan; Universitas Brawijaya, Electrical Engineering Department, Indonesia