Revisiting Visual Model Robustness: A Frequency Long-Tailed Distribution View
Zhiyu Lin, Yifei Gao, Yunfan Yang, Jitao Sang
摘要
A widely discussed hypothesis regarding the cause of visual models’ lack of robustness is that they can exploit human-imperceptible high-frequency components (HFC) in images, which in turn leads to model vulnerabilities, such as the adversarial examples. However, (1) inconsistent findings regarding the validation of this hypothesis reflect in a limited understanding of HFC, and (2) solutions inspired by the hypothesis tend to involve a robustness-accuracy trade-off and leaning towards suppressing the model’s learning on HFC. In this paper, inspired by the long-tailed characteristic observed in frequency spectrum, we first formally define the HFC from long-tailed perspective and then revisit the relationship between HFC and model robustness. In the frequency long-tailed scenario, experimental results on common datasets and various network structures consistently indicate that models in standard training exhibit high sensitivity to HFC. We investigate the reason of the sensitivity, which reflects in model’s under-fitting behavior on HFC. Furthermore, the cause of the model’s under-fitting behavior is attributed to the limited information content in HFC. Based on these findings, we propose a Ba lance S pectrum S ampling (BaSS) strategy, which effectively counteracts the long-tailed effect and enhances the model’s learning on HFC. Extensive experimental results demonstrate that our method achieves a substantially better robustness-accuracy trade-off when combined with existing defense methods, while also indicating the potential of encouraging HFC learning in improving model performance.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper16
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph 等ICLR 2020 · 被引用 1,572 次
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey 等ICLR 2020 · 被引用 829 次
- Improving Robustness using Generated DataSven Gowal, Sylvestre-Alvise Rebuffi, Olivia Wiles, Florian Stimberg 等NeurIPS 2021 · 被引用 384 次
- Unsupervised Speech RecognitionAlexei Baevski, Wei-Ning Hsu, Alexis Conneau, Michael AuliNeurIPS 2021 · 被引用 309 次
相关 Paper
- Adversarial Robustness Under Long-Tailed DistributionTong Wu, Ziwei Liu, Qingqiu Huang, Yu Wang 等CVPR 2021
- High-Frequency Component Helps Explain the Generalization of Convolutional Neural NetworksHaohan Wang, Xindi Wu, Zeyi Huang, Eric P. XingCVPR 2020
- TAET: Two-Stage Adversarial Equalization Training on Long-Tailed DistributionsYuhang Wang, Junkang Guo, Aolei Liu, Kaihao Wang 等CVPR 2025
- Orthogonal Uncertainty Representation of Data Manifold for Robust Long-Tailed LearningYanbiao Ma, Licheng Jiao, Fang Liu, Shuyuan Yang 等ACM MM 2023 · 被引用 8 次
- Taming the Long Tail: Rebalancing Adversarial Training via Adaptive PerturbationLilin Zhang, Yimo Guo, Yue Li, Jiancheng Shi 等CVPR 2026 · 被引用 1 次
