Self-Supervised Adversarial Training via Diverse Augmented Queries and Self-Supervised Double Perturbation
Ruize Zhang, Sheng Tang, Juan Cao
Abstract
Recently, there have been some works studying self-supervised adversarial training, a learning paradigm that learns robust features without labels. While those works have narrowed the performance gap between self-supervised adversarial training (SAT) and supervised adversarial training (supervised AT), a well-established formulation of SAT and its connections with supervised AT are under-explored. Based on a simple SAT benchmark, we find that SAT still faces the problem of large robust generalization gap and degradation on natural samples. We hypothesize this is due to the lack of data complexity and model regularization and propose a method named as DAQ-SDP (Diverse Augmented Queries Self-supervised Double Perturbation). We first challenge the previous conclusion that complex data augmentations degrade robustness in SAT by using diversely augmented samples as queries to guide adversarial training. Inspired by previous works in supervised AT, we then incorporate a self-supervised double perturbation scheme to self-supervised learning (SSL), which promotes robustness transferable to downstream classification. Our work can be seamlessly combined with models pretrained by different SSL frameworks without revising the learning objectives and helps to bridge the gap between SAT and AT. Our method also improves both robust and natural accuracies across different SSL frameworks. Our code is available at https://github.com/rzzhang222/DAQ-SDP.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9ba3ad96-b987-40d9-b2b9-98ae1e2f0c8dCited by top-tier papers1
Ask how each one uses itBuilds on21
- A Simple Framework for Contrastive Learning of Visual RepresentationsTing Chen, Simon Kornblith, Mohammad Norouzi, Geoffrey E. HintonICML 2020 · 24,064 citations
- Bootstrap Your Own Latent - A New Approach to Self-Supervised LearningJean-Bastien Grill, Florian Strub, Florent Altché, Corentin Tallec et al.NeurIPS 2020 · 9,171 citations
- RandAugment: Practical Automated Data Augmentation with a Reduced Search SpaceEkin Dogus Cubuk, Barret Zoph, Jonathon Shlens, Quoc LeNeurIPS 2020 · 4,453 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 917 citations
Related papers
- 3SAT: A Simple Self-Supervised Adversarial Training FrameworkJiang Fang, Haonan He, Jiyan Sun, Jiadong Fu et al.AAAI 2025 · 3 citations
- Efficient and Effective Augmentation Strategy for Adversarial TrainingSravanti Addepalli, Samyak Jain, Venkatesh Babu R.NeurIPS 2022 · 77 citations
- Rethinking the Effect of Data Augmentation in Adversarial Contrastive LearningRundong Luo, Yifei Wang, Yisen WangICLR 2023 · 2 citations
- Weakly Supervised Contrastive Adversarial Training for Learning Robust Features from Semi-supervised DataLilin Zhang, Chengpei Wu, Ning YangCVPR 2025
- Soften to Defend: Towards Adversarial Robustness via Self-Guided Label RefinementZhuorong Li, Daiwei Yu, Lina Wei, Canghong Jin et al.CVPR 2024
