paper-with-me

홈 › Papers

Simple Post-Training Robustness Using Test Time Augmentations and Random Forest

2021-09-16 · Gilad Cohen, Raja Giryes

Although Deep Neural Networks (DNNs) achieve excellent performance on many real-world tasks, they are highly vulnerable to adversarial attacks. A leading defense against such attacks is adversarial training, a technique in which a DNN is trained to be robust to adversarial attacks by introducing adversarial noise to its input. This procedure is effective but must be done during the training phase. In this work, we propose Augmented Random Forest (ARF), a simple and easy-to-use strategy for robustifying an existing pretrained DNN without modifying its weights. For every image, we generate randomized test time augmentations by applying diverse color, blur, noise, and geometric transforms. Then we use the DNN's logits output to train a simple random forest to predict the real class label. Our method achieves state-of-the-art adversarial robustness on a diversity of white and black box attacks with minimal compromise on the natural images' classification. We test ARF also against numerous adaptive white-box attacks and it shows excellent results when combined with adversarial training. Code is available at https://github.com/giladcohen/ARF.

📄 PDF Abstract BibTeX arXiv:2109.08191

Code (2)

giladcohen/arf 공식 구현 pytorch
giladcohen/katana 공식 구현 pytorch

Tasks

Adversarial RobustnessDiversity

Methods 이 논문이 사용한 방법론

Test 설명 없음

Similar Papers 제목 키워드 기반

Understanding and mitigating difficulties in posterior predictive evaluation

2024-05-30 · Abhinav Agrawal, Justin Domke

Predictive posterior densities (PPDs) are of interest in approximate Bayesian inference. Typically, these are estimated by simple Monte Carlo (MC) averages using samples from the approximate posterior. We observe that th…

Bayesian Inference

Minimum Distance Summaries for Robust Neural Posterior Estimation

2026-02-09 · Sherman Khoo, Dennis Prangle, Song Liu, Mark Beaumont arxiv

Simulation-based inference (SBI) enables amortized Bayesian inference by first training a neural posterior estimator (NPE) on prior-simulator pairs, typically through low-dimensional summary statistics, which can then be…

Test-time AdaptationBayesian Inference

Improving Black-box Robustness with In-Context Rewriting

2024-02-13 · Kyle O'Brien, Nathan Ng, Isha Puri, Jorge Mendez 외

Machine learning models for text classification often excel on in-distribution (ID) data but struggle with unseen out-of-distribution (OOD) inputs. Most techniques for improving OOD robustness are not applicable to setti…

News Classificationtext-classificationText Classification

What should post-training optimize? A test-time scaling law perspective

2026-05-11 · Muheng Li, Jian Qian, Wenlong Mou arxiv

Large language models are increasingly deployed with test-time strategies: sample $N$ responses, score them with a reward model or verifier, and return the best. This deployment rule exposes a mismatch in post-training: …

An Evidence-Based Post-Hoc Adjustment Framework for Anomaly Detection Under Data Contamination

2025-10-24 · Sukanya Patra, Souhaib Ben Taieb arxiv

Unsupervised anomaly detection (AD) methods typically assume clean training data, yet real-world datasets often contain undetected or mislabeled anomalies, leading to significant performance degradation. Existing solutio…

Unsupervised Anomaly DetectionTest-time Adaptation