Label Noise in Adversarial Training: A Novel Perspective to Study Robust Overfitting
Chengyu Dong, Liyuan Liu, Jingbo Shang
Abstract
We show that label noise exists in adversarial training. Such label noise is due to the mismatch between the true label distribution of adversarial examples and the label inherited from clean examples - the true label distribution is distorted by the adversarial perturbation, but is neglected by the common practice that inherits labels from clean examples. Recognizing label noise sheds insights on the prevalence of robust overfitting in adversarial training, and explains its intriguing dependence on perturbation radius and data quality. Also, our label noise perspective aligns well with our observations of the epoch-wise double descent in adversarial training. Guided by our analyses, we proposed a method to automatically calibrate the label to address the label noise and robust overfitting. Our method achieves consistent performance improvements across various models and datasets without introducing new hyper-parameters or additional tuning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d4584e55-53ae-445b-a96c-3b5f3466dafeCited by top-tier papers8
- Annealing Self-Distillation Rectification Improves Adversarial TrainingYu-Yu Wu, Hung-Jui Wang, Shang-Tse ChenICLR 2024 · 10 citations
- Meta-Learning Dynamic Center Distance: Hard Sample Mining for Learning with Noisy LabelsChenyu Mu, Yijun Qu, Jiexi Yan, Erkun Yang et al.ICCV 2025 · 2 citations
- FrameShield: Adversarially Robust Video Anomaly DetectionMojtaba Nafez, Mobina Poulaei, Nikan Vasei, Bardia Soltani Moakhar et al.NeurIPS 2025 · 2 citations
- Over-Training with Mixup May Hurt GeneralizationZixuan Liu, Ziqiao Wang, Hongyu Guo, Yongyi MaoICLR 2023 · 2 citations
- Soften to Defend: Towards Adversarial Robustness via Self-Guided Label RefinementZhuorong Li, Daiwei Yu, Lina Wei, Canghong Jin et al.CVPR 2024
Builds on10
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Deep Double Descent: Where Bigger Models and More Data HurtPreetum Nakkiran, Gal Kaplun, Yamini Bansal, Tristan Yang et al.ICLR 2020 · 1,108 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- Attacks Which Do Not Kill Training Make Adversarial Learning StrongerJingfeng Zhang, Xilie Xu, Bo Han, Gang Niu et al.ICML 2020 · 452 citations
- Rethinking Bias-Variance Trade-off for Generalization of Neural NetworksZitong Yang, Yaodong Yu, Chong You, Jacob Steinhardt et al.ICML 2020 · 219 citations
Related papers
- Self-Adaptive Training: beyond Empirical Risk MinimizationLang Huang, Chao Zhang, Hongyang ZhangNeurIPS 2020 · 256 citations
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 917 citations
- How Benign is Benign Overfitting ?Amartya Sanyal, Puneet K. Dokania, Varun Kanade, Philip H. S. TorrICLR 2021 · 61 citations
- Benign Overfitting in Adversarial Training of Neural NetworksYunjuan Wang, Kaibo Zhang, Raman AroraICML 2024 · 3 citations
- Improving Calibration through the Relationship with Adversarial RobustnessYao Qin, Xuezhi Wang, Alex Beutel, Ed H. ChiNeurIPS 2021 · 32 citations
