Adversarially Robust Models may not Transfer Better: Sufficient Conditions for Domain Transferability from the View of Regularization
Xiaojun Xu, Jacky Y. Zhang, Evelyn Ma, Hyun Ho Son, Sanmi Koyejo, Bo Li
摘要
Machine learning (ML) robustness and domain generalization are fundamentally correlated: they essentially concern data distribution shifts under adversarial and natural settings, respectively. On one hand, recent studies show that more robust (adversarially trained) models are more generalizable. On the other hand, there is a lack of theoretical understanding of their fundamental connections. In this paper, we explore the relationship between regularization and domain transferability considering different factors such as norm regularization and data augmentations (DA). We propose a general theoretical framework proving that factors involving the model function class regularization are sufficient conditions for relative domain transferability. Our analysis implies that ``robustness"is neither necessary nor sufficient for transferability; rather, regularization is a more fundamental perspective for understanding domain transferability. We then discuss popular DA protocols (including adversarial training) and show when they can be viewed as the function class regularization under certain conditions and therefore improve generalization. We conduct extensive experiments to verify our theoretical findings and show several counterexamples where robustness and generalization are negatively correlated on different datasets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- Better Safe Than Sorry: Preventing Delusive Adversaries with Adversarial TrainingLue Tao, Lei Feng, Jinfeng Yi, Sheng-Jun Huang 等NeurIPS 2021 · 被引用 90 次
- Why Does Little Robustness Help? A Further Step Towards Understanding Adversarial TransferabilityYechao Zhang, Shengshan Hu, Leo Yu Zhang, Junyu Shi 等S&P 2024 · 被引用 36 次
- Efficient Adversarial Contrastive Learning via Robustness-Aware Coreset SelectionXilie Xu, Jingfeng Zhang, Feng Liu, Masashi Sugiyama 等NeurIPS 2023 · 被引用 26 次
- Improving Generalization of Universal Adversarial Perturbation via Dynamic Maximin OptimizationYechao Zhang, Yingzhe Xu, Junyu Shi, Leo Yu Zhang 等AAAI 2025 · 被引用 7 次
- Adversarially Robust Multi-task Representation LearningAustin Watkins, Thanh Nguyen-Tang, Enayat Ullah, Raman AroraNeurIPS 2024 · 被引用 5 次
它引用的顶会 Paper11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 被引用 797 次
- A Group-Theoretic Framework for Data AugmentationShuxiao Chen, Edgar Dobriban, Jane H. LeeNeurIPS 2020 · 被引用 254 次
- f-Domain Adversarial Learning: Theory and AlgorithmsDavid Acuna, Guojun Zhang, Marc T. Law, Sanja FidlerICML 2021 · 被引用 77 次
- TRS: Transferability Reduced Ensemble via Promoting Gradient Diversity and Model SmoothnessZhuolin Yang, Linyi Li, Xiaojun Xu, Shiliang Zuo 等NeurIPS 2021 · 被引用 76 次
相关 Paper
- A Flat Minima Perspective on Understanding Augmentations and Model RobustnessWeebum Yoo, Sung Whan YoonAAAI 2026 · 被引用 1 次
- Adversarial Training Helps Transfer Learning via Better RepresentationsZhun Deng, Linjun Zhang, Kailas Vodrahalli, Kenji Kawaguchi 等NeurIPS 2021 · 被引用 60 次
- Generalised Lipschitz Regularisation Equals Distributional RobustnessZac Cranko, Zhan Shi, Xinhua Zhang, Richard Nock 等ICML 2021 · 被引用 26 次
- Certifying Better Robust Generalization for Unsupervised Domain AdaptationZhiqiang Gao, Shufei Zhang, Kaizhu Huang, Qiufeng Wang 等ACM MM 2022 · 被引用 4 次
- ARMOURED: Adversarially Robust MOdels using Unlabeled data by REgularizing DiversityKangkang Lu, Cuong Manh Nguyen, Xun Xu, Kiran Chari 等ICLR 2021 · 被引用 2 次
