Adversarially Robust Models may not Transfer Better: Sufficient Conditions for Domain Transferability from the View of Regularization
Xiaojun Xu, Jacky Y. Zhang, Evelyn Ma, Hyun Ho Son, Sanmi Koyejo, Bo Li
Abstract
Machine learning (ML) robustness and domain generalization are fundamentally correlated: they essentially concern data distribution shifts under adversarial and natural settings, respectively. On one hand, recent studies show that more robust (adversarially trained) models are more generalizable. On the other hand, there is a lack of theoretical understanding of their fundamental connections. In this paper, we explore the relationship between regularization and domain transferability considering different factors such as norm regularization and data augmentations (DA). We propose a general theoretical framework proving that factors involving the model function class regularization are sufficient conditions for relative domain transferability. Our analysis implies that ``robustness"is neither necessary nor sufficient for transferability; rather, regularization is a more fundamental perspective for understanding domain transferability. We then discuss popular DA protocols (including adversarial training) and show when they can be viewed as the function class regularization under certain conditions and therefore improve generalization. We conduct extensive experiments to verify our theoretical findings and show several counterexamples where robustness and generalization are negatively correlated on different datasets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 108d7d86-0cc1-415c-8452-47cbf1d4c368Cited by top-tier papers6
- Better Safe Than Sorry: Preventing Delusive Adversaries with Adversarial TrainingLue Tao, Lei Feng, Jinfeng Yi, Sheng-Jun Huang et al.NeurIPS 2021 · 90 citations
- Why Does Little Robustness Help? A Further Step Towards Understanding Adversarial TransferabilityYechao Zhang, Shengshan Hu, Leo Yu Zhang, Junyu Shi et al.S&P 2024 · 36 citations
- Efficient Adversarial Contrastive Learning via Robustness-Aware Coreset SelectionXilie Xu, Jingfeng Zhang, Feng Liu, Masashi Sugiyama et al.NeurIPS 2023 · 26 citations
- Improving Generalization of Universal Adversarial Perturbation via Dynamic Maximin OptimizationYechao Zhang, Yingzhe Xu, Junyu Shi, Leo Yu Zhang et al.AAAI 2025 · 7 citations
- Adversarially Robust Multi-task Representation LearningAustin Watkins, Thanh Nguyen-Tang, Enayat Ullah, Raman AroraNeurIPS 2024 · 5 citations
Builds on11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
- A Group-Theoretic Framework for Data AugmentationShuxiao Chen, Edgar Dobriban, Jane H. LeeNeurIPS 2020 · 254 citations
- f-Domain Adversarial Learning: Theory and AlgorithmsDavid Acuna, Guojun Zhang, Marc T. Law, Sanja FidlerICML 2021 · 77 citations
- TRS: Transferability Reduced Ensemble via Promoting Gradient Diversity and Model SmoothnessZhuolin Yang, Linyi Li, Xiaojun Xu, Shiliang Zuo et al.NeurIPS 2021 · 76 citations
Related papers
- A Flat Minima Perspective on Understanding Augmentations and Model RobustnessWeebum Yoo, Sung Whan YoonAAAI 2026 · 1 citation
- Adversarial Training Helps Transfer Learning via Better RepresentationsZhun Deng, Linjun Zhang, Kailas Vodrahalli, Kenji Kawaguchi et al.NeurIPS 2021 · 60 citations
- Generalised Lipschitz Regularisation Equals Distributional RobustnessZac Cranko, Zhan Shi, Xinhua Zhang, Richard Nock et al.ICML 2021 · 26 citations
- Certifying Better Robust Generalization for Unsupervised Domain AdaptationZhiqiang Gao, Shufei Zhang, Kaizhu Huang, Qiufeng Wang et al.ACM MM 2022 · 4 citations
- ARMOURED: Adversarially Robust MOdels using Unlabeled data by REgularizing DiversityKangkang Lu, Cuong Manh Nguyen, Xun Xu, Kiran Chari et al.ICLR 2021 · 2 citations
