Zero-cost Proxy for Adversarial Robustness Evaluation
Yuqi Feng, Yuwei Ou, Jiahao Fan, Yanan Sun
摘要
Deep neural networks (DNNs) easily cause security issues due to the lack of adversarial robustness. An emerging research topic for this problem is to design adversarially robust architectures via neural architecture search (NAS), i.e., robust NAS. However, robust NAS needs to train numerous DNNs for robustness estimation, making the search process prohibitively expensive. In this paper, we propose a zero-cost proxy to evaluate the adversarial robustness without training. Specifically, the proposed zero-cost proxy formulates the upper bound of adversarial loss, which can directly reflect the adversarial robustness. The formulation involves only the initialized weights of DNNs, thus the training process is no longer needed. Moreover, we theoretically justify the validity of the proposed proxy based on the theory of neural tangent kernel and input loss landscape. Experimental results show that the proposed zero-cost proxy can bring more than speedup compared with the state-of-the-art robust NAS methods, while the searched architecture has superior robustness and transferability under white-box and black-box attacks. Furthermore, compared with the state-of-the-art zero-cost proxies, the calculation of the proposed method has the strongest correlation with adversarial robustness. Our source code is available at https://github.com/fyqsama/Robust_ZCP.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Vulnerable Data-Aware Adversarial TrainingYuqi Feng, Jiahao Fan, Yanan SunNeurIPS 2025 · 被引用 2 次
- TRNAS: A Training-Free Robust Neural Architecture SearchYeming Yang, Qingling Zhu, Jianping Luo, Ka-Chun Wong 等ICCV 2025 · 被引用 1 次
它引用的顶会 Paper29
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha 等S&P 2016 · 被引用 3,275 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 被引用 1,765 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
相关 Paper
- Generalizable Lightweight Proxy for Robust NAS against Diverse PerturbationsHyeonjeong Ha, Minseon Kim, Sung Ju HwangNeurIPS 2023 · 被引用 12 次
- Towards Accurate and Robust Architectures via Neural Architecture SearchYuwei Ou, Yuqi Feng, Yanan SunCVPR 2024 · 被引用 8 次
- ArchLock: Locking DNN Transferability at the Architecture Level with a Zero-Cost Binary PredictorTong Zhou, Shaolei Ren, Xiaolin XuICLR 2024 · 被引用 5 次
- Extensible and Efficient Proxy for Neural Architecture SearchYuhong Li, Jiajie Li, Cong Hao, Pan Li 等ICCV 2023 · 被引用 8 次
- DSRNA: Differentiable Search of Robust Neural ArchitecturesRamtin Hosseini, Xingyi Yang, Pengtao XieCVPR 2021
