Adversarial Self-Training Improves Robustness and Generalization for Gradual Domain Adaptation
Lianghe Shi, Weiwei Liu
Abstract
Gradual Domain Adaptation (GDA), in which the learner is provided with additional intermediate domains, has been theoretically and empirically studied in many contexts. Despite its vital role in security-critical scenarios, the adversarial robustness of the GDA model remains unexplored. In this paper, we adopt the effective gradual self-training method and replace vanilla self-training with adversarial self-training (AST). AST first predicts labels on the unlabeled data and then adversarially trains the model on the pseudo-labeled distribution. Intriguingly, we find that gradual AST improves not only adversarial accuracy but also clean accuracy on the target domain. We reveal that this is because adversarial training (AT) performs better than standard training when the pseudo-labels contain a portion of incorrect labels. Accordingly, we first present the generalization error bounds for gradual AST in a multiclass classification setting. We then use the optimal value of the Subset Sum Problem to bridge the standard error on a real distribution and the adversarial error on a pseudo-labeled distribution. The result indicates that AT may obtain a tighter bound than standard training on data with incorrect pseudo-labels. We further present an example of a conditional Gaussian distribution to provide more insights into why gradual AST can improve the clean accuracy for GDA.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 813eef72-e113-426d-a129-19eabce0f52dCited by top-tier papers11
- Samba: Severity-aware Recurrent Modeling for Cross-domain Medical Image GradingQi Bi, Jingjun Yi, Hao Zheng, Wei Ji et al.NeurIPS 2024 · 10 citations
- A Closer Look at Curriculum Adversarial Training: From an Online PerspectiveLianghe Shi, Weiwei LiuAAAI 2024 · 7 citations
- Bayesian Domain Adaptation with Gaussian Mixture Domain-IndexingYanfang Ling, Jiyong Li, Lingbo Li, Shangsong LiangNeurIPS 2024 · 7 citations
- DRF: Improving Certified Robustness via Distributional Robustness FrameworkZekai Wang, Zhengyu Zhou, Weiwei LiuAAAI 2024 · 7 citations
- A Provable Decision Rule for Out-of-Distribution DetectionXinsong Ma, Xin Zou, Weiwei LiuICML 2024 · 4 citations
Builds on15
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- FixMatch: Simplifying Semi-Supervised Learning with Consistency and ConfidenceKihyuk Sohn, David Berthelot, Nicholas Carlini, Zizhao Zhang et al.NeurIPS 2020 · 5,129 citations
- Confidence Regularized Self-TrainingYang Zou, Zhiding Yu, Xiaofeng Liu, B. V. K. Vijaya Kumar et al.ICCV 2019 · 901 citations
- Do Adversarially Robust ImageNet Models Transfer Better?Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor et al.NeurIPS 2020 · 506 citations
- Attacks Which Do Not Kill Training Make Adversarial Learning StrongerJingfeng Zhang, Xilie Xu, Bo Han, Gang Niu et al.ICML 2020 · 452 citations
Related papers
- Self-Training with Dynamic Weighting for Robust Gradual Domain AdaptationZixi Wang, Yushe Cao, Yubo Huang, Jinzhu Wei et al.NeurIPS 2025 · 3 citations
- Understanding Gradual Domain Adaptation: Improved Analysis, Optimal Path and BeyondHaoxiang Wang, Bo Li, Han ZhaoICML 2022 · 48 citations
- SRoUDA: Meta Self-Training for Robust Unsupervised Domain AdaptationWanqing Zhu, Jia-Li Yin, Bo-Hao Chen, Ximeng LiuAAAI 2023 · 14 citations
- Toward Improving Robustness and Accuracy in Unsupervised Domain AdaptationAishwarya Soni, Tanima DuttaAAAI 2025 · 3 citations
- Adversarial-Learned Loss for Domain AdaptationMinghao Chen, Shuai Zhao, Haifeng Liu, Deng CaiAAAI 2020 · 195 citations
