Revisiting Visual Model Robustness: A Frequency Long-Tailed Distribution View
Zhiyu Lin, Yifei Gao, Yunfan Yang, Jitao Sang
Abstract
A widely discussed hypothesis regarding the cause of visual models’ lack of robustness is that they can exploit human-imperceptible high-frequency components (HFC) in images, which in turn leads to model vulnerabilities, such as the adversarial examples. However, (1) inconsistent findings regarding the validation of this hypothesis reflect in a limited understanding of HFC, and (2) solutions inspired by the hypothesis tend to involve a robustness-accuracy trade-off and leaning towards suppressing the model’s learning on HFC. In this paper, inspired by the long-tailed characteristic observed in frequency spectrum, we first formally define the HFC from long-tailed perspective and then revisit the relationship between HFC and model robustness. In the frequency long-tailed scenario, experimental results on common datasets and various network structures consistently indicate that models in standard training exhibit high sensitivity to HFC. We investigate the reason of the sensitivity, which reflects in model’s under-fitting behavior on HFC. Furthermore, the cause of the model’s under-fitting behavior is attributed to the limited information content in HFC. Based on these findings, we propose a Ba lance S pectrum S ampling (BaSS) strategy, which effectively counteracts the long-tailed effect and enhances the model’s learning on HFC. Extensive experimental results demonstrate that our method achieves a substantially better robustness-accuracy trade-off when combined with existing defense methods, while also indicating the potential of encouraging HFC learning in improving model performance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1ecaf8a7-fb25-4dbd-b4dc-f49f1795063fCited by top-tier papers1
Ask how each one uses itBuilds on16
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph et al.ICLR 2020 · 1,572 citations
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey et al.ICLR 2020 · 829 citations
- Improving Robustness using Generated DataSven Gowal, Sylvestre-Alvise Rebuffi, Olivia Wiles, Florian Stimberg et al.NeurIPS 2021 · 384 citations
- Unsupervised Speech RecognitionAlexei Baevski, Wei-Ning Hsu, Alexis Conneau, Michael AuliNeurIPS 2021 · 309 citations
Related papers
- Adversarial Robustness Under Long-Tailed DistributionTong Wu, Ziwei Liu, Qingqiu Huang, Yu Wang et al.CVPR 2021
- High-Frequency Component Helps Explain the Generalization of Convolutional Neural NetworksHaohan Wang, Xindi Wu, Zeyi Huang, Eric P. XingCVPR 2020
- TAET: Two-Stage Adversarial Equalization Training on Long-Tailed DistributionsYuhang Wang, Junkang Guo, Aolei Liu, Kaihao Wang et al.CVPR 2025
- Orthogonal Uncertainty Representation of Data Manifold for Robust Long-Tailed LearningYanbiao Ma, Licheng Jiao, Fang Liu, Shuyuan Yang et al.ACM MM 2023 · 8 citations
- Taming the Long Tail: Rebalancing Adversarial Training via Adaptive PerturbationLilin Zhang, Yimo Guo, Yue Li, Jiancheng Shi et al.CVPR 2026 · 1 citation
