ROSE: Robust Selective Fine-tuning for Pre-trained Language Models
Lan Jiang, Hao Zhou, Yankai Lin, Peng Li, Jie Zhou, Rui Jiang
Abstract
Even though the large-scale language models have achieved excellent performances, they suffer from various adversarial attacks. A large body of defense methods has been proposed. However, they are still limited due to redundant attack search spaces and the inability to defend against various types of attacks. In this work, we present a novel fine-tuning approach called RObust SEletive fine-tuning (ROSE) to address this issue. ROSE conducts selective updates when adapting pre-trained models to downstream tasks, filtering out invaluable and unrobust updates of parameters. Specifically, we propose two strategies: the first-order and second-order ROSE for selecting target robust parameters. The experimental results show that ROSE achieves significant improvements in adversarial robustness on various downstream NLP tasks, and the ensemble method even surpasses both variants above. Furthermore, ROSE can be easily incorporated into existing fine-tuning methods to improve their adversarial robustness further. The empirical analysis confirms that ROSE eliminates unrobust spurious updates during fine-tuning, leading to solutions corresponding to flatter and wider optima than the conventional method. Code is available at https: //github.com/jiangllan/ROSE .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4a77b4ad-b735-42ff-a6c1-eed7506498feCited by top-tier papers3
- Don't Retrain, Just Rewrite: Countering Adversarial Perturbations by Rewriting TextAshim Gupta, Carter Wood Blum, Temma Choji, Yingjie Fei et al.ACL 2023 · 7 citations
- Evaluating Concurrent Robustness of Language Models Across Diverse Challenge SetsVatsal Gupta, Pranshu Pandya, Tushar Kataria, Vivek Gupta et al.EMNLP 2024 · 1 citation
- Analyzing and Reducing the Performance Gap in Cross-Lingual Transfer with Fine-tuning Slow and FastYiduo Guo, Yaobo Liang, Dongyan Zhao, Bing Liu et al.ACL 2023
Builds on18
- SimCSE: Simple Contrastive Learning of Sentence EmbeddingsTianyu Gao, Xingcheng Yao, Danqi ChenEMNLP 2021 · 2,496 citations
- Is BERT Really Robust? A Strong Baseline for Natural Language Attack on Text Classification and EntailmentDi Jin, Zhijing Jin, Joey Tianyi Zhou, Peter SzolovitsAAAI 2020 · 1,333 citations
- R-Drop: Regularized Dropout for Neural NetworksXiaobo Liang, Lijun Wu, Juntao Li, Yue Wang et al.NeurIPS 2021 · 610 citations
- Adversarial NLI: A New Benchmark for Natural Language UnderstandingYixin Nie, Adina Williams, Emily Dinan, Mohit Bansal et al.ACL 2020 · 602 citations
- FreeLB: Enhanced Adversarial Training for Natural Language UnderstandingChen Zhu, Yu Cheng, Zhe Gan, Siqi Sun et al.ICLR 2020 · 502 citations
Related papers
- How Should Pre-Trained Language Models Be Fine-Tuned Towards Adversarial Robustness?Xinshuai Dong, Anh Tuan Luu, Min Lin, Shuicheng Yan et al.NeurIPS 2021 · 80 citations
- Model-tuning Via Prompts Makes NLP Models Adversarially RobustMrigank Raman, Pratyush Maini, J. Zico Kolter, Zachary C. Lipton et al.EMNLP 2023 · 7 citations
- Token-level Data Selection for Safe LLM Fine-tuningYanping Li, Zhening Liu, Zijian Li, Zehong Lin et al.ICLR 2026 · 4 citations
- Fine-Tuning Pre-Trained Language Models Effectively by Optimizing Subnetworks AdaptivelyHaojie Zhang, Ge Li, Jia Li, Zhongjin Zhang et al.NeurIPS 2022 · 43 citations
- Robustifying Zero-Shot Vision Language Models by Subspaces AlignmentJunhao Dong, Piotr Koniusz, Liaoyuan Feng, Yifei Zhang et al.ICCV 2025 · 2 citations
