Improving Sustainability of Adversarial Examples in Class-Incremental Learning
Taifeng Liu, Xinjing Liu, Liangqiu Dong, Yang Liu, Yilong Yang, Zhuo Ma
Abstract
Current adversarial examples (AEs) are typically designed for static models. However, with the wide application of Class-Incremental Learning (CIL), models are no longer static and need to be updated with new data distributed and labeled differently from the old ones. As a result, existing AEs often fail after CIL updates due to significant domain drift. In this paper, we propose SAE to enhance the sustainability of AEs against CIL. The core idea of SAE is to enhance the robustness of AE semantics against domain drift by making them more similar to the target class while distinguishing them from all other classes. Achieving this is challenging, as relying solely on the initial CIL model to optimize AE semantics often leads to overfitting. To resolve the problem, we propose a Semantic Correction Module. This module encourages the AE semantics to be generalized, based on a visual-language model capable of producing universal semantics. Additionally, it incorporates the CIL model to correct the optimization direction of the AE semantics, guiding them closer to the target class. To further reduce fluctuations in AE semantics, we propose a Filtering-and-Augmentation Module, which first identifies non-target examples with target-class semantics in the latent space and then augments them to foster more stable semantics. Comprehensive experiments demonstrate that SAE outperforms baselines by an average of 31.28% when updated with a 9-fold increase in the number of classes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on18
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Dark Experience for General Continual Learning: a Strong, Simple BaselinePietro Buzzega, Matteo Boschini, Angelo Porrello, Davide Abati et al.NeurIPS 2020 · 1,494 citations
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 1,295 citations
- Learning to Prompt for Continual LearningZifeng Wang, Zizhao Zhang, Chen-Yu Lee, Han Zhang et al.CVPR 2022 · 635 citations
- RMM: Reinforced Memory Management for Class-Incremental LearningYaoyao Liu, Bernt Schiele, Qianru SunNeurIPS 2021 · 125 citations
Related papers
- Bring Evanescent Representations to Life in Lifelong Class Incremental LearningMarco Toldo, Mete OzayCVPR 2022 · 34 citations
- Expandable Subspace Ensemble for Pre-Trained Model-Based Class-Incremental LearningDa-Wei Zhou, Hai-Long Sun, Han-Jia Ye, De-Chuan ZhanCVPR 2024
- Attacks on Continual Semantic Segmentation by Perturbing Incremental SamplesZhidong Yu, Wei Yang, Xike Xie, Zhenbo ShiAAAI 2024 · 1 citation
- XIL: Cross-Expanding Incremental LearningHeayoun Choi, Hyundong Jin, Eunwoo KimICLR 2026
- Navigating Semantic Drift in Task-Agnostic Class-Incremental LearningFangwen Wu, Lechao Cheng, Shengeng Tang, Xiaofeng Zhu et al.ICML 2025
