TWINS: A Fine-Tuning Framework for Improved Transferability of Adversarial Robustness and Generalization
Ziquan Liu, Yi Xu, Xiangyang Ji, Antoni B. Chan
Abstract
Recent years have seen the ever-increasing importance of pre-trained models and their downstream training in deep learning research and applications. At the same time, the defense for adversarial examples has been mainly investigated in the context of training from random initialization on simple classification tasks. To better exploit the potential of pre-trained models in adversarial robustness, this paper focuses on the fine-tuning of an adversarially pre-trained model in various classification tasks. Existing research has shown that since the robust pre-trained model has already learned a robust feature extractor, the crucial question is how to maintain the robustness in the pre-trained model when learning the downstream task. We study the modelbased and data-based approaches for this goal and find that the two common approaches cannot achieve the objective of improving both generalization and adversarial robustness. Thus, we propose a novel statistics-based approach, Two-WIng NormliSation (TWINS) fine-tuning framework, which consists of two neural networks where one of them keeps the population means and variances of pre-training data in the batch normalization layers. Besides the robust information transfer, TWINS increases the effective learning rate without hurting the training stability since the relationship between a weight norm and its gradient norm in standard batch normalization layer is broken, resulting in a faster escape from the sub-optimal initialization and alleviating the robust overfitting. Finally, TWINS is shown to be effective on a wide range of image classification datasets in terms of both generalization and robustness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c6eed7bc-e242-4a93-afe6-04bcbae2088bCited by top-tier papers10
- The Pitfalls and Promise of Conformal Inference Under Adversarial AttacksZiquan Liu, Yufei Cui, Yan Yan, Yi Xu et al.ICML 2024 · 9 citations
- AutoLoRa: An Automated Robust Fine-Tuning FrameworkXilie Xu, Jingfeng Zhang, Mohan S. KankanhalliICLR 2024 · 5 citations
- Mitigating Feature Gap for Adversarial Robustness by Feature DisentanglementNuoyan Zhou, Dawei Zhou, Decheng Liu, Nannan Wang et al.AAAI 2025 · 3 citations
- Learning from Mistakes: Self-correct Adversarial Training for Chinese Unnatural Text CorrectionXuan Feng, Tianlong Gu, Xiaoli Liu, Liang ChangAAAI 2025 · 2 citations
- On the Robustness Tradeoff in Fine-TuningKunyang Li, Jean-Charles Noirot Ferrand, Ryan Sheatsley, Blaine Hoak et al.ICCV 2025 · 2 citations
Builds on30
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
Related papers
- ImageNet Pre-training Also Transfers Non-robustnessJiaming Zhang, Jitao Sang, Qi Yi, Yunfan Yang et al.AAAI 2023 · 6 citations
- CARTL: Cooperative Adversarially-Robust Transfer LearningDian Chen, Hongxin Hu, Qian Wang, Yinli Li et al.ICML 2021 · 15 citations
- Intriguing Properties of Adversarial Training at ScaleCihang Xie, Alan L. YuilleICLR 2020 · 66 citations
- Stochastic NormalizationZhi Kou, Kaichao You, Mingsheng Long, Jianmin WangNeurIPS 2020 · 138 citations
- Removing Batch Normalization Boosts Adversarial TrainingHaotao Wang, Aston Zhang, Shuai Zheng, Xingjian Shi et al.ICML 2022 · 51 citations
