跳到主要导航 跳到搜索 跳到主要内容

Robust long-tailed recognition with distribution-aware adversarial example generation

  • Bo Li
  • , Yongqiang Yao
  • , Jingru Tan*
  • , Dandan Zhu
  • , Ruihao Gong
  • , Ye Luo
  • , Jianwei Lu
  • *此作品的通讯作者
  • Tongji University
  • SenseTime Group Limited
  • Central South University
  • Shanghai University of Traditional Chinese Medicine

科研成果: 期刊稿件文章同行评审

摘要

Confronting adversarial attacks and data imbalances, attaining adversarial robustness under long-tailed distribution presents a challenging problem. Adversarial training (AT) is a conventional solution for enhancing adversarial robustness, which generates adversarial examples (AEs) in a generation phase and subsequently trains on these AEs in a training phase. Existing long-tailed adversarial learning methods follow the AT framework and rebalance the AE classification in the training phase. However, few of them realize the impact of the long-tailed distribution on the generation phase. In this paper, we delve into the generation phase and uncover its imbalance across different classes. We evaluate the generation quality for different classes by comparing the differences between their generated AEs and natural examples. Our findings reveal that these differences are less pronounced in tail classes compared to head classes, indicating their inferior generation quality. To solve this problem, we propose the novel Distribution-Aware Adversarial Example Generation (DAG) method, which balances the AE generation for different classes using a Virtual Example Creator (VEC) and a Gradient-Guided Calibrator (GGC). The VEC creates virtual examples to introduce more adversarial perturbations for different classes, while the GGC calibrates the creation process to enhance the focus on tail classes based on their generation quality, effectively addressing the imbalance problem. Extensive experiments on three long-tailed adversarial benchmarks across five attack scenarios demonstrate DAG's effectiveness. On CIFAR-100-LT, DAG outperforms the previous RoBal by 4.0 points under the projected gradient descent (PGD) attack, highlighting its superiority in adversarial scenarios.

源语言英语
文章编号106932
期刊Neural Networks
184
DOI
出版状态已出版 - 4月 2025

指纹

探究 'Robust long-tailed recognition with distribution-aware adversarial example generation' 的科研主题。它们共同构成独一无二的指纹。

引用此