Robust long-tailed recognition with distribution-aware adversarial example generation

  • Bo Li
  • , Yongqiang Yao
  • , Jingru Tan*
  • , Dandan Zhu
  • , Ruihao Gong
  • , Ye Luo
  • , Jianwei Lu
  • *Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

1 Scopus citations

Abstract

Confronting adversarial attacks and data imbalances, attaining adversarial robustness under long-tailed distribution presents a challenging problem. Adversarial training (AT) is a conventional solution for enhancing adversarial robustness, which generates adversarial examples (AEs) in a generation phase and subsequently trains on these AEs in a training phase. Existing long-tailed adversarial learning methods follow the AT framework and rebalance the AE classification in the training phase. However, few of them realize the impact of the long-tailed distribution on the generation phase. In this paper, we delve into the generation phase and uncover its imbalance across different classes. We evaluate the generation quality for different classes by comparing the differences between their generated AEs and natural examples. Our findings reveal that these differences are less pronounced in tail classes compared to head classes, indicating their inferior generation quality. To solve this problem, we propose the novel Distribution-Aware Adversarial Example Generation (DAG) method, which balances the AE generation for different classes using a Virtual Example Creator (VEC) and a Gradient-Guided Calibrator (GGC). The VEC creates virtual examples to introduce more adversarial perturbations for different classes, while the GGC calibrates the creation process to enhance the focus on tail classes based on their generation quality, effectively addressing the imbalance problem. Extensive experiments on three long-tailed adversarial benchmarks across five attack scenarios demonstrate DAG's effectiveness. On CIFAR-100-LT, DAG outperforms the previous RoBal by 4.0 points under the projected gradient descent (PGD) attack, highlighting its superiority in adversarial scenarios.

Original languageEnglish
Article number106932
JournalNeural Networks
Volume184
DOIs
StatePublished - Apr 2025

Keywords

  • Adversarial example generation
  • Adversarial robustness
  • Distribution-aware learning
  • Long-tailed recognition

Fingerprint

Dive into the research topics of 'Robust long-tailed recognition with distribution-aware adversarial example generation'. Together they form a unique fingerprint.

Cite this