Adversarial Robustness Under Long-Tailed Distribution
Tong Wu, Ziwei Liu, Qingqiu Huang, Yu Wang, Dahua Lin
Abstract
Adversarial robustness has attracted extensive studies recently by revealing the vulnerability and intrinsic characteristics of deep networks. However, existing works on adversarial robustness mainly focus on balanced datasets, while real-world data usually exhibits a long-tailed distribution. To push adversarial robustness towards more realistic scenarios, in this work we investigate the adversarial vulnerability as well as defense under long-tailed distributions. In particular, we first reveal the negative impacts induced by imbalanced data on both recognition performance and adversarial robustness, uncovering the intrinsic challenges of this problem. We then perform a systematic study on existing long-tailed recognition methods in conjunction with the adversarial training framework. Several valuable observations are obtained: 1) natural accuracy is relatively easy to improve, 2) fake gain of robust accuracy exists under unreliable evaluation, and 3) boundary error limits the promotion of robustness. Inspired by these observations, we propose a clean yet effective framework, RoBal, which consists of two dedicated modules, a scale-invariant classifier and data re-balancing via both margin engineering at training stage and boundary adjustment during inference. Extensive experiments demonstrate the superiority of our approach over other state-of-the-art defense methods. To our best knowledge, we are the first to tackle adversarial robustness under long-tailed distributions, which we believe would be a significant step towards real-world robustness. Our code is available at: https://github . com/wutong16/Adversarial_Long-Tail.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers31
- On Model Calibration for Long-Tailed Object Detection and Instance SegmentationTai-Yu Pan, Cheng Zhang, Yandong Li, Hexiang Hu et al.NeurIPS 2021 · 56 citations
- CalFAT: Calibrated Federated Adversarial Training with Label SkewnessChen Chen, Yuchen Liu, Xingjun Ma, Lingjuan LyuNeurIPS 2022 · 53 citations
- Generalized Logit Adjustment: Calibrating Fine-tuned Models by Removing Label Bias in Foundation ModelsBeier Zhu, Kaihua Tang, Qianru Sun, Hanwang ZhangNeurIPS 2023 · 50 citations
- ScaleLong: Towards More Stable Training of Diffusion Model via Scaling Network Long Skip ConnectionZhongzhan Huang, Pan Zhou, Shuicheng Yan, Liang LinNeurIPS 2023 · 41 citations
- COLA: Cross-city Mobility Transformer for Human Trajectory SimulationYu Wang, Tongya Zheng, Yuxuan Liang, Shunyu Liu et al.WWW 2024 · 37 citations
Builds on18
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Decoupling Representation and Classifier for Long-Tailed RecognitionBingyi Kang, Saining Xie, Marcus Rohrbach, Zhicheng Yan et al.ICLR 2020 · 1,496 citations
- Long-tail learning via logit adjustmentAditya Krishna Menon, Sadeep Jayasumana, Ankit Singh Rawat, Himanshu Jain et al.ICLR 2021 · 937 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
Related papers
- TAET: Two-Stage Adversarial Equalization Training on Long-Tailed DistributionsYuhang Wang, Junkang Guo, Aolei Liu, Kaihao Wang et al.CVPR 2025
- Taming the Long Tail: Rebalancing Adversarial Training via Adaptive PerturbationLilin Zhang, Yimo Guo, Yue Li, Jiancheng Shi et al.CVPR 2026 · 1 citation
- Revisiting Adversarial Training Under Long-Tailed DistributionsXinli Yue, Ningping Mou, Qian Wang, Lingchen ZhaoCVPR 2024 · 14 citations
- Long-tailed Adversarial Training with Self-DistillationSeungju Cho, Hongsin Lee, Changick KimICLR 2025
- FedCART: Tackling Long-Tailed Distributions in Federated Adversarial Training via Classifier RefinementYuchen Qin, Yizhi Zhou, Junxiao Wang, Xin Xie et al.CVPR 2026
