Revisiting adapters with adversarial training
Sylvestre-Alvise Rebuffi, Francesco Croce, Sven Gowal
Abstract
While adversarial training is generally used as a defense mechanism, recent works show that it can also act as a regularizer. By co-training a neural network on clean and adversarial inputs, it is possible to improve classification accuracy on the clean, non-adversarial inputs. We demonstrate that, contrary to previous findings, it is not necessary to separate batch statistics when co-training on clean and adversarial inputs, and that it is sufficient to use adapters with few domain-specific parameters for each type of input. We establish that using the classification token of a Vision Transformer (ViT) as an adapter is enough to match the classification performance of dual normalization layers, while using significantly less additional parameters. First, we improve upon the top-1 accuracy of a non-adversarially trained ViT-B16 model by +1.12% on ImageNet (reaching 83.76% top-1 accuracy). Second, and more importantly, we show that training with adapters enables model soups through linear combinations of the clean and adversarial tokens. These model soups, which we call adversarial model soups, allow us to trade-off between clean and robust accuracy without sacrificing efficiency. Finally, we show that we can easily adapt the resulting models in the face of distribution shifts. Our ViT-B16 obtains top-1 accuracies on ImageNet variants that are on average +4.00% better than those obtained with Masked Autoencoders.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9d63bb0a-c012-4cf1-b9a9-2f3663daf9d2Cited by top-tier papers7
- Revisiting Adversarial Training for ImageNet: Architectures, Training and Generalization across Threat ModelsNaman Deep Singh, Francesco Croce, Matthias HeinNeurIPS 2023 · 119 citations
- Layer-wise linear mode connectivityLinara Adilova, Maksym Andriushchenko, Michael Kamp, Asja Fischer et al.ICLR 2024 · 22 citations
- Distilling Out-of-Distribution Robustness from Vision-Language Foundation ModelsAndy Zhou, Jindong Wang, Yu-Xiong Wang, Haohan WangNeurIPS 2023 · 14 citations
- Beyond Pretrained Features: Noisy Image Modeling Provides Adversarial DefenseZunzhi You, Daochang Liu, Bohyung Han, Chang XuNeurIPS 2023 · 9 citations
- Mixture of Adversarial LoRAs: Boosting Robust Generalization in Meta-TuningXu Yang, Chen Liu, Ying WeiNeurIPS 2024 · 1 citation
Builds on19
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
- RandAugment: Practical Automated Data Augmentation with a Reduced Search SpaceEkin Dogus Cubuk, Barret Zoph, Jonathon Shlens, Quoc LeNeurIPS 2020 · 4,453 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
Related papers
- Seasoning Model Soups for Robustness to Adversarial and Natural Distribution ShiftsFrancesco Croce, Sylvestre-Alvise Rebuffi, Evan Shelhamer, Sven GowalCVPR 2023
- Benign Overfitting in Adversarial Training for Vision TransformersJiaming Zhang, Meng Ding, Shaopeng Fu, Jingfeng Zhang et al.ICML 2026 · 1 citation
- Trade-off between Robustness and Accuracy of Vision TransformersYanxi Li, Chang XuCVPR 2023
- Pyramid Adversarial Training Improves ViT PerformanceCharles Herrmann, Kyle Sargent, Lu Jiang, Ramin Zabih et al.CVPR 2022 · 40 citations
- When Adversarial Training Meets Vision Transformers: Recipes from Training to ArchitectureYichuan Mo, Dongxian Wu, Yifei Wang, Yiwen Guo et al.NeurIPS 2022 · 109 citations
