MixMatch: A Holistic Approach to Semi-Supervised Learning
David Berthelot, Nicholas Carlini, Ian Goodfellow, Nicolas Papernot, Avital Oliver, Colin Raffel
Introduction
Much of the recent success in training large, deep neural networks is thanks in part to the existence of large labeled datasets. Yet, collecting labeled data is expensive for many learning tasks because it necessarily involves expert knowledge. This is perhaps best illustrated by medical tasks where measurements call for expensive machinery and labels are the fruit of a time-consuming analysis that draws from multiple human experts. Furthermore, data labels may contain private information. In comparison, in many tasks it is much easier or cheaper to obtain unlabeled data.
Semi-supervised learning (SSL) seeks to largely alleviate the need for labeled data by allowing a model to leverage unlabeled data. Many recent approaches for semi-supervised learning add a loss term which is computed on unlabeled data and encourages the model to generalize better to unseen data. In much recent work, this loss term falls into one of three classes (discussed further in Section 2): entropy minimization —which encourages the model to output confident predictions on unlabeled data; consistency regularization—which encourages the model to produce the same output distribution when its inputs are perturbed; and generic regularization—which encourages the model to generalize well and avoid overfitting the training data.
In this paper, we introduce , an SSL algorithm which introduces a single loss that gracefully unifies these dominant approaches to semi-supervised learning. Unlike previous methods, targets all the properties at once which we find leads to the following benefits:
Experimentally, we show that obtains state-of-the-art results on all standard image benchmarks (section 4.2), and reducing the error rate on CIFAR-10 by a factor of 4;
We further show in an ablation study that is greater than the sum of its parts;
We demonstrate in section 4.3 that is useful for differentially private learning, enabling students in the PATE framework to obtain new state-of-the-art results that simultaneously strengthen both privacy guarantees and accuracy.
In short, introduces a unified loss term for unlabeled data that seamlessly reduces entropy while maintaining consistency and remaining compatible with traditional regularization techniques.
Related Work
To set the stage for , we first introduce existing methods for SSL. We focus mainly on those which are currently state-of-the-art and that builds on; there is a wide literature on SSL techniques that we do not discuss here (e.g., “transductive” models , graph-based methods , generative modeling , etc.). More comprehensive overviews are provided in . In the following, we will refer to a generic model which produces a distribution over class labels for an input with parameters .
A common regularization technique in supervised learning is data augmentation, which applies input transformations assumed to leave class semantics unaffected. For example, in image classification, it is common to elastically deform or add noise to an input image, which can dramatically change the pixel content of an image without altering its label . Roughly speaking, this can artificially expand the size of a training set by generating a near-infinite stream of new, modified data. Consistency regularization applies data augmentation to semi-supervised learning by leveraging the idea that a classifier should output the same class distribution for an unlabeled example even after it has been augmented. More formally, consistency regularization enforces that an unlabeled example should be classified the same as , an augmentation of itself.
In the simplest case, for unlabeled points , prior work adds the loss term
Note that is a stochastic transformation, so the two terms in eq. 1 are not identical. “Mean Teacher” replaces one of the terms in eq. 1 with the output of the model using an exponential moving average of model parameter values. This provides a more stable target and was found empirically to significantly improve results. A drawback to these approaches is that they use domain-specific data augmentation strategies. “Virtual Adversarial Training” (VAT) addresses this by instead computing an additive perturbation to apply to the input which maximally changes the output class distribution. MixMatch utilizes a form of consistency regularization through the use of standard data augmentation for images (random horizontal flips and crops).
2 Entropy Minimization
A common underlying assumption in many semi-supervised learning methods is that the classifier’s decision boundary should not pass through high-density regions of the marginal data distribution. One way to enforce this is to require that the classifier output low-entropy predictions on unlabeled data. This is done explicitly in with a loss term which minimizes the entropy of for unlabeled data . This form of entropy minimization was combined with VAT in to obtain stronger results. “Pseudo-Label” does entropy minimization implicitly by constructing hard (1-hot) labels from high-confidence predictions on unlabeled data and using these as training targets in a standard cross-entropy loss. MixMatch also implicitly achieves entropy minimization through the use of a “sharpening” function on the target distribution for unlabeled data, described in section 3.2.
3 Traditional Regularization
Regularization refers to the general approach of imposing a constraint on a model to make it harder to memorize the training data and therefore hopefully make it generalize better to unseen data . We use weight decay which penalizes the norm of the model parameters . We also use in to encourage convex behavior “between” examples. We utilize as both as a regularizer (applied to labeled datapoints) and a semi-supervised learning method (applied to unlabeled datapoints). has been previously applied to semi-supervised learning; in particular, the concurrent work of uses a subset of the methodology used in MixMatch. We clarify the differences in our ablation study (section 4.2.3).
MixMatch
In this section, we introduce , our proposed semi-supervised learning method. is a “holistic” approach which incorporates ideas and components from the dominant paradigms for SSL discussed in section 2. Given a batch of labeled examples with one-hot targets (representing one of possible labels) and an equally-sized batch of unlabeled examples, produces a processed batch of augmented labeled examples and a batch of augmented unlabeled examples with “guessed” labels . and are then used in computing separate labeled and unlabeled loss terms. More formally, the combined loss for semi-supervised learning is defined as
where is the cross-entropy between distributions and , and , , , and are hyperparameters described below. The full algorithm is provided in algorithm 1, and a diagram of the label guessing process is shown in fig. 1. Next, we describe each part of .
As is typical in many SSL methods, we use data augmentation both on labeled and unlabeled data. For each in the batch of labeled data , we generate a transformed version (algorithm 1, line 3). For each in the batch of unlabeled data , we generate augmentations (algorithm 1, line 5). We use these individual augmentations to generate a “guessed label” for each , through a process we describe in the following subsection.
2 Label Guessing
For each unlabeled example in , produces a “guess” for the example’s label using the model’s predictions. This guess is later used in the unsupervised loss term. To do so, we compute the average of the model’s predicted class distributions across all the augmentations of by
in algorithm 1, line 7. Using data augmentation to obtain an artificial target for an unlabeled example is common in consistency regularization methods .
In generating a label guess, we perform one additional step inspired by the success of entropy minimization in semi-supervised learning (discussed in section 2.2). Given the average prediction over augmentations , we apply a sharpening function to reduce the entropy of the label distribution. In practice, for the sharpening function, we use the common approach of adjusting the “temperature” of this categorical distribution , which is defined as the operation
where is some input categorical distribution (specifically in , is the average class prediction over augmentations , as shown in algorithm 1, line 8) and is a hyperparameter. As , the output of will approach a Dirac (“one-hot”) distribution. Since we will later use as a target for the model’s prediction for an augmentation of , lowering the temperature encourages the model to produce lower-entropy predictions.
3 MixUp
We use for semi-supervised learning, and unlike past work for SSL we mix both labeled examples and unlabeled examples with label guesses (generated as described in section 3.2). To be compatible with our separate loss terms, we define a slightly modified version of . For a pair of two examples with their corresponding labels probabilities we compute by
where is a hyperparameter. Vanilla omits eq. 9 (i.e. it sets ). Given that labeled and unlabeled examples are concatenated in the same batch, we need to preserve the order of the batch to compute individual loss components appropriately. This is achieved by eq. 9 which ensures that is closer to than to . To apply , we first collect all augmented labeled examples with their labels and all unlabeled examples with their guessed labels into
(algorithm 1, lines 10–11). Then, we combine these collections and shuffle the result to form which will serve as a data source for (algorithm 1, line 12). For each the example-label pair in , we compute and add the result to the collection (algorithm 1, line 13). We compute for , intentionally using the remainder of that was not used in the construction of (algorithm 1, line 14). To summarize, transforms into , a collection of labeled examples which have had data augmentation and (potentially mixed with an unlabeled example) applied. Similarly, is transformed into , a collection of multiple augmentations of each unlabeled example with corresponding label guesses.
4 Loss Function
Given our processed batches and , we use the standard semi-supervised loss shown in eqs. 3, 4 and 5. Equation 5 combines the typical cross-entropy loss between labels and model predictions from with the squared loss on predictions and guessed labels from . We use this loss in eq. 4 (the multiclass Brier score ) because, unlike the cross-entropy, it is bounded and less sensitive to incorrect predictions. For this reason, it is often used as the unlabeled data loss in SSL as well as a measure of predictive uncertainty . We do not propagate gradients through computing the guessed labels, as is standard
5 Hyperparameters
Since combines multiple mechanisms for leveraging unlabeled data, it introduces various hyperparameters – specifically, the sharpening temperature , number of unlabeled augmentations , parameter for in , and the unsupervised loss weight . In practice, semi-supervised learning methods with many hyperparameters can be problematic because cross-validation is difficult with small validation sets . However, we find in practice that most of ’s hyperparameters can be fixed and do not need to be tuned on a per-experiment or per-dataset basis. Specifically, for all experiments we set and . Further, we only change and on a per-dataset basis; we found that and are good starting points for tuning. In all experiments, we linearly ramp up to its maximum value over the first steps of training as is common practice .
Experiments
We test the effectiveness of on standard SSL benchmarks (section 4.2). Our ablation study teases apart the contribution of each of ’s components (section 4.2.3). As an additional application, we consider privacy-preserving learning in section 4.3.
Unless otherwise noted, in all experiments we use the “Wide ResNet-28” model from . Our implementation of the model and training procedure closely matches that of (including using 5000 examples to select the hyperparameters), except for the following differences: First, instead of decaying the learning rate, we evaluate models using an exponential moving average of their parameters with a decay rate of . Second, we apply a weight decay of at each update for the Wide ResNet-28 model. Finally, we checkpoint every training samples and report the median error rate of the last 20 checkpoints. This simplifies the analysis at a potential cost to accuracy by, for example, averaging checkpoints or choosing the checkpoint with the lowest validation error.
2 Semi-Supervised Learning
First, we evaluate the effectiveness of on four standard benchmark datasets: CIFAR-10 and CIFAR-100 , SVHN , and STL-10 . Standard practice for evaluating semi-supervised learning on the first three datasets is to treat most of the dataset as unlabeled and use a small portion as labeled data. STL-10 is a dataset specifically designed for SSL, with 5,000 labeled images and 100,000 unlabeled images which are drawn from a slightly different distribution than the labeled data.
As baselines, we consider the four methods considered in (-Model , Mean Teacher , Virtual Adversarial Training , and Pseudo-Label ) which are described in section 2. We also use on its own as a baseline. is designed as a regularizer for supervised learning, so we modify it for SSL by applying it both to augmented labeled examples and augmented unlabeled examples with their corresponding predictions. In accordance with standard usage of , we use a cross-entropy loss between the -generated guess label and the model’s prediction. As advocated by , we reimplemented each of these methods in the same codebase and applied them to the same model (described in section 4.1) to ensure a fair comparison. We re-tuned the hyperparameters for each baseline method, which generally resulted in a marginal accuracy improvement compared to those in , thereby providing a more competitive experimental setting for testing out .
2.2 Results
For CIFAR-10, we evaluate the accuracy of each method with a varying number of labeled examples from to (as is standard practice). The results can be seen in fig. 2. We used for CIFAR-10. We created 5 splits for each number of labeled points, each with a different random seed. Each model was trained on each split and the error rates were reported by the mean and variance across splits. We find that outperforms all other methods by a significant margin, for example reaching an error rate of with labels. For reference, on the same model, fully supervised training on all samples achieves an error rate of . Furthermore, obtains an error rate of with only labels. For comparison, at labels the next-best-performing method (VAT ) achieves an error rate of , over higher than considering that is the error limit obtained on our model with fully supervised learning. In addition, at labels the next-best-performing method (Mean Teacher ) obtains an error rate of , which suggests that can achieve similar performance with only as many labels. We believe that the most interesting comparisons are with very few labeled data points since it reveals the method’s sample efficiency which is central to SSL.
Some prior work has also considered the use of a larger, million-parameter model. Our base model, as used in , has only million parameters which confounds comparison with these results. For a more reasonable comparison to these results, we measure the effect of increasing the width of our base ResNet model and evaluate ’s performance on a 28-layer Wide Resnet model which has filters per layer, resulting in million parameters. We also evaluate on this larger model on CIFAR-100 with labels, to compare to the corresponding result from . The results are shown in table 2. In general, matches or outperforms the best results from , though we note that the comparison still remains problematic due to the fact that the model from also uses more sophisticated “shake-shake” regularization . For this model, we used a weight decay of . We used for CIFAR-10 and for CIFAR-100.
As with CIFAR-10, we evaluate the performance of each SSL method on SVHN with a varying number of labels from to . As is standard practice, we first consider the setting where the -example training set is split into labeled and unlabeled data. The results are shown in fig. 3. We used . Here again the models were evaluated on 5 splits for each number of labeled points, each with a different random seed. We found ’s performance to be relatively constant (and better than all other methods) across all amounts of labeled data. Surprisingly, after additional tuning we were able to obtain extremely good performance from Mean Teacher , though its error rate was consistently slightly higher than ’s.
Note that SVHN has two training sets: train and extra. In fully-supervised learning, both sets are concatenated to form the full training set ( samples). In SSL, for historical reasons the extra set was left aside and only train was used ( samples). We argue that leveraging both train and extra for the unlabeled data is more interesting since it exhibits a higher ratio of unlabeled samples over labeled ones. We report error rates for both SVHN and SVHN+Extra in table 3. For SVHN+Extra we used and a lower weight decay of due to the larger amount of available data. We found that on both training sets, nearly matches the fully-supervised performance on the same training set almost immediately – for example, achieves an error rate of with only 250 labels on SVHN+Extra compared to the fully-supervised performance of . Interestingly, on SVHN+Extra outperformed fully supervised training on SVHN without extra ( error) for every labeled data amount considered. To emphasize the importance of this, consider the following scenario: You have examples from SVHN with examples labeled and are given a choice: You can either obtain more unlabeled data and use or obtain more labeled data and use fully-supervised learning. Our results suggest that obtaining additional unlabeled data and using is more effective, which conveniently is likely much cheaper than obtaining more labels.
STL-10 contains training examples aimed at being used with predefined folds (we use the first 5 only) with examples each. However, some prior work trains on all examples. We thus compare in both experimental settings. With examples surpasses both the state-of-the-art for examples as well as the state-of-the-art using all labeled examples. Note that none of the baselines in table 2 use the same experimental setup (i.e. model), so it is difficult to directly compare the results; however, because obtains the lowest error by a factor of two, we take this to be a vote in confidence of our method. We used .
2.3 Ablation Study
Since combines various semi-supervised learning mechanisms, it has a good deal in common with existing methods in the literature. As a result, we study the effect of removing or adding components in order to provide additional insight into what makes performant. Specifically, we measure the effect of
using the mean class distribution over augmentations or using the class distribution for a single augmentation (i.e. setting )
removing temperature sharpening (i.e. setting )
using an exponential moving average (EMA) of model parameters when producing guessed labels, as is done by Mean Teacher
performing between labeled examples only, unlabeled examples only, and without mixing across labeled and unlabeled examples
using Interpolation Consistency Training , which can be seen as a special case of this ablation study where only unlabeled mixup is used, no sharpening is applied and EMA parameters are used for label guessing.
We carried out the ablation on CIFAR-10 with and labels; the results are shown in table 4. We find that each component contributes to ’s performance, with the most dramatic differences in the -label setting. Despite Mean Teacher’s effectiveness on SVHN (fig. 3), we found that using a similar EMA of parameter values hurt ’s performance slightly.
3 Privacy-Preserving Learning and Generalization
Learning with privacy allows us to measure our approach’s ability to generalize. Indeed, protecting the privacy of training data amounts to proving that the model does not overfit: a learning algorithm is said to be differentially private (the most widely accepted technical definition of privacy) if adding, modifying, or removing any of its training samples is guaranteed not to result in a statistically significant difference in the model parameters learned . For this reason, learning with differential privacy is, in practice, a form of regularization . Each training data access constitutes a potential privacy leakage, encoded as the pair of the input and its label. Hence, approaches for deep learning from private training data, such as DP-SGD and PATE , benefit from accessing as few labeled private training points as possible when computing updates to the model parameters. Semi-supervised learning is a natural fit for this setting.
We use the PATE framework for learning with privacy. A student is trained in a semi-supervised way from public unlabeled data, part of which is labeled by an ensemble of teachers with access to private labeled training data. The fewer labels a student requires to reach a fixed accuracy, the stronger is the privacy guarantee it provides. Teachers use a noisy voting mechanism to respond to label queries from the student, and they may choose not to provide a label when they cannot reach a sufficiently strong consensus. For this reason, if improves the performance of PATE, it would also illustrate ’s improved generalization from few canonical exemplars of each class.
We compare the accuracy-privacy trade-off achieved by to a VAT baseline on SVHN. VAT achieved the previous state-of-the-art of test accuracy for a privacy loss of . Because performs well with few labeled points, it is able to achieve test accuracy for a much smaller privacy loss of . Because is used to measure the degree of privacy, the improvement is approximately , a significant improvement. A privacy loss below 1 corresponds to a much stronger privacy guarantee. Note that in the private training setting the student model only uses 10,000 total examples.
Conclusion
We introduced , a semi-supervised learning method which combines ideas and components from the current dominant paradigms for SSL. Through extensive experiments on semi-supervised and privacy-preserving learning, we found that exhibited significantly improved performance compared to other methods in all settings we studied, often by a factor of two or more reduction in error rate. In future work, we are interested in incorporating additional ideas from the semi-supervised learning literature into hybrid methods and continuing to explore which components result in effective algorithms. Separately, most modern work on semi-supervised learning algorithms is evaluated on image benchmarks; we are interested in exploring the effectiveness of in other domains.
We would like to thank Balaji Lakshminarayanan for his helpful theoretical insights.
References
Appendix A Notation and definitions
Appendix B Tabular results
Training the same model with supervised learning on the entire -example training set achieved an error rate of .
B.2 SVHN
Training the same model with supervised learning on the entire -example training set achieved an error rate of .
B.3 SVHN+Extra
Training the same model with supervised learning on the entire -example training set achieved an error rate of .
Appendix C 13-layer ConvNet results
Early work on semi-supervised learning used a 13-layer convolutional network architecture . In table 8 we present results on a similar architecture. We caution against comparing these numbers directly to previous work as we use a different implementation and training process .