paper-with-me

Papers

Wasserstein distributional adversarial training for deep neural networks

2025-02-13 · Xingjian Bai, Guangyi He, Yifan Jiang, Jan Obloj

Design of adversarial attacks for deep neural networks, as well as methods of adversarial training against them, are subject of intense research. In this paper, we propose methods to train against distributional attack threats, extending the TRADES method used for pointwise attacks. Our approach leverages recent contributions and relies on sensitivity analysis for Wasserstein distributionally robust optimization problems. We introduce an efficient fine-tuning method which can be deployed on a previously trained model. We test our methods on a range of pre-trained models on RobustBench. These experimental results demonstrate the additional training enhances Wasserstein distributional robustness, while maintaining original levels of pointwise robustness, even for already very successful networks. The improvements are less marked for models pre-trained using huge synthetic datasets of 20-100M images. However, remarkably, sometimes our methods are still able to improve their performance even when trained using only the original training dataset (50k images).

📄 PDF Abstract BibTeX arXiv:2502.09352

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

A Unified Wasserstein Distributional Robustness Framework for Adversarial Training

2022-02-27 · ICLR 2022 4 · Tuan Anh Bui, Trung Le, Quan Tran, He Zhao 외

It is well-known that deep neural networks (DNNs) are susceptible to adversarial attacks, exposing a severe fragility of deep learning systems. As the result, adversarial training (AT) method, by incorporating adversaria…

Provable Robust Overfitting Mitigation in Wasserstein Distributionally Robust Optimization

2025-03-06 · Shuang Liu, Yihan Wang, Yifan Zhu, Yibo Miao 외

Wasserstein distributionally robust optimization (WDRO) optimizes against worst-case distributional shifts within a specified uncertainty set, leading to enhanced generalization on unseen adversarial examples, compared t…

Distributionally and Adversarially Robust Logistic Regression via Intersecting Wasserstein Balls

2024-07-18 · Aras Selvi, Eleonora Kreacic, Mohsen Ghassemi, Vamsi Potluru 외

Adversarially robust optimization (ARO) has emerged as the *de facto* standard for training models that hedge against adversarial attacks in the test stage. While these models are robust against adversarial attacks, they…

regression

Wasserstein distributional robustness of neural networks

2023-06-16 · NeurIPS 2023 11 · Xingjian Bai, Guangyi He, Yifan Jiang, Jan Obloj

Deep neural networks are known to be vulnerable to adversarial attacks (AA). For an image recognition task, this means that a small perturbation of the original can result in the image being misclassified. Design of such…

Statistical Guarantees for Distributionally Robust Optimization with Optimal Transport and OT-Regularized Divergences

2026-03-29 · Jeremiah Birrell, Xiaoxi Shen arxiv

We study finite-sample statistical performance guarantees for distributionally robust optimization (DRO) with optimal transport (OT) and OT-regularized divergence model neighborhoods. Specifically, we derive concentratio…

Adversarial Robustness