Robust Perception through Equivariance
Chengzhi Mao, Lingyu Zhang, Abhishek Vaibhav Joshi, Junfeng Yang, Hao Wang, Carl Vondrick
Abstract
Deep networks for computer vision are not reliable when they encounter adversarial examples. In this paper, we introduce a framework that uses the dense intrinsic constraints in natural images to robustify inference. By introducing constraints at inference time, we can shift the burden of robustness from training to the inference algorithm, thereby allowing the model to adjust dynamically to each individual image's unique and potentially novel characteristics at inference time. Among different constraints, we find that equivariance-based constraints are most effective, because they allow dense constraints in the feature space without overly constraining the representation at a fine-grained level. Our theoretical results validate the importance of having such dense constraints at inference time. Our empirical experiments show that restoring feature equivariance at inference time defends against worst-case adversarial perturbations. The method obtains improved adversarial robustness on four datasets (ImageNet, Cityscapes, PASCAL VOC, and MS-COCO) on image recognition, semantic segmentation, and instance segmentation tasks. Project page is available at equi4robust.cs.columbia.edu.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 87de89c0-8fc6-44db-bb29-332cd685da3dCited by top-tier papers4
- Convolutional Visual Prompt for Robust Visual PerceptionYun-Yun Tsai, Chengzhi Mao, Junfeng YangNeurIPS 2023 · 25 citations
- Understanding Zero-shot Adversarial Robustness for Large-Scale ModelsChengzhi Mao, Scott Geng, Junfeng Yang, Xin Wang et al.ICLR 2023 · 10 citations
- Structure-Aware Semantic Discrepancy and Consistency for 3D Medical Image Self-Supervised LearningTan Pan, Zhaorui Tan, Kaiyu Guo, Dongli Xu et al.ICCV 2025 · 2 citations
- Beyond Instance-Level Self-Supervision in 3D Multi-Modal Medical ImagingTan Pan, Shuhao Mei, Yixuan Sun, Kaiyu Guo et al.ICML 2026
Builds on21
- A Simple Framework for Contrastive Learning of Visual RepresentationsTing Chen, Simon Kornblith, Mohammad Norouzi, Geoffrey E. HintonICML 2020 · 24,064 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- The Many Faces of Robustness: A Critical Analysis of Out-of-Distribution GeneralizationDan Hendrycks, Steven Basart, Norman Mu, Saurav Kadavath et al.ICCV 2021 · 2,294 citations
Related papers
- Adversarial Attacks are Reversible with Natural SupervisionChengzhi Mao, Mia Chiquier, Hao Wang, Junfeng Yang et al.ICCV 2021 · 66 citations
- Evidential Learning-based Certainty Estimation for Robust Dense Feature MatchingLile Cai, Chuan-Sheng Foo, Xun Xu, Zaiwang Gu et al.ICLR 2025
- Equivariant Adaptation of Large Pretrained ModelsArnab Kumar Mondal, Siba Smarak Panigrahi, Oumar Kaba, Sai Mudumba et al.NeurIPS 2023 · 49 citations
- Towards Robustness of Deep Neural Networks via RegularizationYao Li, Martin Renqiang Min, Thomas C. M. Lee, Wenchao Yu et al.ICCV 2021 · 8 citations
- Anytime Dense Prediction with Confidence AdaptivityZhuang Liu, Zhiqiu Xu, Hung-Ju Wang, Trevor Darrell et al.ICLR 2022 · 24 citations
