Revisiting Adversarial Training Under Long-Tailed Distributions
Xinli Yue, Ningping Mou, Qian Wang, Lingchen Zhao
Abstract
Deep neural networks are vulnerable to adversarial attacks, leading to erroneous outputs. Adversarial training has been recognized as one of the most effective methods to counter such attacks. However, existing adversarial training techniques have predominantly been evaluated on balanced datasets, whereas real-world data often exhibit a long-tailed distribution, casting doubt on the efficacy of these methods in practical scenarios. In this paper, we delve into the performance of adversarial training under long-tailed distributions. Through an analysis of the prior method “RoBal” (Wu et al., CVPR'21), we discover that utilizing Balanced Softmax Loss (BSL) alone can obtain comparable performance to the complete RoBal approach while significantly reducing the training overhead. Then, we reveal that adversarial training under long-tailed distributions also suffers from robust overfitting similar to uniform distributions. We explore utilizing data augmentation to mitigate this issue and unexpectedly discover that, unlike results obtained with balanced data, data augmentation not only effectively alleviates robust overfitting but also significantly improves robustness. We further identify that the improvement is attributed to the increased diversity of training data. Extensive experiments further corroborate that data augmentation alone can significantly improve robustness. Finally, building on these findings, we demonstrate that compared to RoBal, the combination of BSL and data augmentation leads to a +6.66% improvement in model robustness under AutoAttack on CIFAR-10-LT. Our code is available at: https://github.com/NISPLab/AT-BSL.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 12d9d218-ba09-458c-bd5e-4d9fdf33c2a3Cited by top-tier papers10
- Enhancing Robustness in Incremental Learning with Adversarial TrainingSeungju Cho, Hongsin Lee, Changick KimAAAI 2025 · 4 citations
- Alleviating Performance Disparity in Adversarial Spatiotemporal Graph Learning Under Zero-Inflated DistributionSongran Bai, Yuheng Ji, Yue Liu, Xingwei Zhang et al.AAAI 2025 · 3 citations
- Mitigating Error Amplification in Fast Adversarial TrainingMengnan Zhao, Lihe Zhang, Bo Wang, Tianhang Zheng et al.CVPR 2026 · 1 citation
- Taming the Long Tail: Rebalancing Adversarial Training via Adaptive PerturbationLilin Zhang, Yimo Guo, Yue Li, Jiancheng Shi et al.CVPR 2026 · 1 citation
- From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed LearningZiang Li, Hongguang Zhang, Juan Wang, Meihui Chen et al.CVPR 2025
Builds on33
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
- RandAugment: Practical Automated Data Augmentation with a Reduced Search SpaceEkin Dogus Cubuk, Barret Zoph, Jonathon Shlens, Quoc LeNeurIPS 2020 · 4,453 citations
- Elucidating the Design Space of Diffusion-Based Generative ModelsTero Karras, Miika Aittala, Timo Aila, Samuli LaineNeurIPS 2022 · 3,959 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
Related papers
- Adversarial Robustness Under Long-Tailed DistributionTong Wu, Ziwei Liu, Qingqiu Huang, Yu Wang et al.CVPR 2021
- TAET: Two-Stage Adversarial Equalization Training on Long-Tailed DistributionsYuhang Wang, Junkang Guo, Aolei Liu, Kaihao Wang et al.CVPR 2025
- Long-tailed Adversarial Training with Self-DistillationSeungju Cho, Hongsin Lee, Changick KimICLR 2025
- Consistency Regularization for Adversarial RobustnessJihoon Tack, Sihyun Yu, Jongheon Jeong, Minseon Kim et al.AAAI 2022 · 75 citations
- LLM-AutoDA: Large Language Model-Driven Automatic Data Augmentation for Long-tailed ProblemsPengkun Wang, Zhe Zhao, Haibin Wen, Fanfu Wang et al.NeurIPS 2024 · 26 citations
