Towards Understanding the Generative Capability of Adversarially Robust Classifiers
Yao Zhu, Jiacheng Ma, Jiacheng Sun, Zewei Chen, Rongxin Jiang, Yaowu Chen, Zhenguo Li
Abstract
Recently, some works found an interesting phenomenon that adversarially robust classifiers can generate good images comparable to generative models. We investigate this phenomenon from an energy perspective and provide a novel explanation. We reformulate adversarial example generation, adversarial training, and image generation in terms of an energy function. We find that adversarial training contributes to obtaining an energy function that is flat and has low energy around the real data, which is the key for generative capability. Based on our new understanding, we further propose a better adversarial training method, Joint Energy Adversarial Training (JEAT), which can generate high-quality images and achieve new state-of-the-art robustness under a wide range of attacks. The Inception Score of the images (CIFAR-10) generated by JEAT is 8.80, much better than original robust classifiers (7.50). In particular, we find that the robustness of JEAT is better than other hybrid models.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e0cba632-5e4f-4210-8323-0adcc65d7265Cited by top-tier papers13
- Boosting Out-of-distribution Detection with Typical FeaturesYao Zhu, Yuefeng Chen, Chuanlong Xie, Xiaodan Li et al.NeurIPS 2022 · 74 citations
- Adversarial Robustness for Unsupervised Domain AdaptationMuhammad Awais, Fengwei Zhou, Hang Xu, Lanqing Hong et al.ICCV 2021 · 46 citations
- Which Models have Perceptually-Aligned Gradients? An Explanation via Off-Manifold RobustnessSuraj Srinivas, Sebastian Bordt, Himabindu LakkarajuNeurIPS 2023 · 24 citations
- MixACM: Mixup-Based Robustness Transfer via Distillation of Activated Channel MapsMuhammad Awais, Fengwei Zhou, Chuanlong Xie, Jiawei Li et al.NeurIPS 2021 · 22 citations
- Defending Black-Box Skeleton-Based Human Activity ClassifiersHe Wang, Yunfeng Diao, Zichang Tan, Guodong GuoAAAI 2023 · 13 citations
Builds on4
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Your classifier is secretly an energy based model and you should treat it like oneWill Grathwohl, Kuan-Chieh Wang, Jörn-Henrik Jacobsen, David Duvenaud et al.ICLR 2020 · 643 citations
- Learning the Stein Discrepancy for Training and Evaluating Energy-Based Models without SamplingWill Grathwohl, Kuan-Chieh Wang, Jörn-Henrik Jacobsen, David Duvenaud et al.ICML 2020 · 93 citations
- Benchmarking Adversarial Robustness on Image ClassificationYinpeng Dong, Qi-An Fu, Xiao Yang, Tianyu Pang et al.CVPR 2020
Related papers
- Your Classifier Can Do More: Towards Balancing the Gaps in Classification, Robustness, and GenerationKaichao Jiang, He Wang, Xiaoshuai Hao, Xiulong Yang et al.CVPR 2026 · 1 citation
- A Unified Contrastive Energy-based Model for Understanding the Generative Ability of Adversarial TrainingYifei Wang, Yisen Wang, Jiansheng Yang, Zhouchen LinICLR 2022 · 19 citations
- Scalable Energy-Based Models via Adversarial Training: Unifying Discrimination and GenerationXuwang Yin, Claire Zhang, Julie Steele, Nir Shavit et al.ICLR 2026 · 1 citation
- Towards Bridging the Performance Gaps of Joint Energy-Based ModelsXiulong Yang, Qing Su, Shihao JiCVPR 2023
- Jacobian Adversarially Regularized Networks for RobustnessAlvin Chan, Yi Tay, Yew-Soon Ong, Jie FuICLR 2020 · 81 citations
