On the Adversarial Robustness of Out-of-distribution Generalization Models
Xin Zou, Weiwei Liu
Abstract
Out-of-distribution (OOD) generalization has attracted increasing research attention in recent years, due to its promising experimental results in real-world applications. Interestingly, we find that existing OOD generalization methods are vulnerable to adversarial attacks. This motivates us to study OOD adversarial robustness. We first present theoretical analyses of OOD adversarial robustness in two different complementary settings. Motivated by the theoretical results, we design two algorithms to improve the OOD adversarial robustness. Finally, we conduct experiments to validate the effectiveness of our proposed algorithms. Our code is available at https://github.com/ZouXinn/OOD-Adv.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers13
- Generalization Bounds for Out-of-distribution GeneralizationXin Zou, Xiuwen Gong, Weiwei LiuICML 2026 · 14 citations
- DRF: Improving Certified Robustness via Distributional Robustness FrameworkZekai Wang, Zhengyu Zhou, Weiwei LiuAAAI 2024 · 7 citations
- Scanning Trojaned Models Using Out-of-Distribution SamplesHossein Mirzaei, Ali Ansari, Bahar Dibaei Nia, Mojtaba Nafez et al.NeurIPS 2024 · 6 citations
- Stability Evaluation through Distributional Perturbation AnalysisJosé H. Blanchet, Peng Cui, Jiajin Li, Jiashuo LiuICML 2024 · 6 citations
- Coverage-Guaranteed Prediction Sets for Out-of-Distribution DataXin Zou, Weiwei LiuAAAI 2024 · 5 citations
Builds on21
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- In Search of Lost Domain GeneralizationIshaan Gulrajani, David Lopez-PazICLR 2021 · 1,416 citations
- Out-of-Distribution Generalization via Risk Extrapolation (REx)David Krueger, Ethan Caballero, Jörn-Henrik Jacobsen, Amy Zhang et al.ICML 2021 · 1,163 citations
- Do Adversarially Robust ImageNet Models Transfer Better?Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor et al.NeurIPS 2020 · 506 citations
Related papers
- OODRobustBench: a Benchmark and Large-Scale Analysis of Adversarial Robustness under Distribution ShiftLin Li, Yifei Wang, Chawin Sitawarin, Michael W. SpratlingICML 2024 · 13 citations
- Improved OOD Generalization via Adversarial Training and PretraingMingyang Yi, Lu Hou, Jiacheng Sun, Lifeng Shang et al.ICML 2021 · 99 citations
- Removing Undesirable Feature Contributions Using Out-of-Distribution DataSaehyung Lee, Changhwa Park, Hyungyu Lee, Jihun Yi et al.ICLR 2021 · 26 citations
- The Best of Both Worlds: On the Dilemma of Out-of-distribution DetectionQingyang Zhang, Qiuxuan Feng, Joey Tianyi Zhou, Yatao Bian et al.NeurIPS 2024
- Your Out-of-Distribution Detection Method is Not Robust!Mohammad Azizmalayeri, Arshia Soltani Moakhar, Arman Zarei, Reihaneh Zohrabi et al.NeurIPS 2022 · 29 citations
