Towards Evaluating the Robustness of Neural Networks Learned by Transduction
Jiefeng Chen, Xi Wu, Yang Guo, Yingyu Liang, Somesh Jha
摘要
There has been emerging interest in using transductive learning for adversarial robustness (Goldwasser et al., NeurIPS 2020; Wu et al., ICML 2020; Wang et al., ArXiv 2021). Compared to traditional defenses, these defense mechanisms "dynamically learn" the model based on test-time input; and theoretically, attacking these defenses reduces to solving a bilevel optimization problem, which poses difficulty in crafting adaptive attacks. In this paper, we examine these defense mechanisms from a principled threat analysis perspective. We formulate and analyze threat models for transductive-learning based defenses, and point out important subtleties. We propose the principle of attacking model space for solving bilevel attack objectives, and present Greedy Model Space Attack (GMSA), an attack framework that can serve as a new baseline for evaluating transductivelearning based defenses. Through systematic evaluation, we show that GMSA, even with weak instantiations, can break previous transductive-learning based defenses, which were resilient to previous attacks, such as AutoAttack. On the positive side, we report a somewhat surprising empirical result of "transductive adversarial training": Adversarially retraining the model using fresh randomness at the test time gives a significant increase in robustness against attacks we consider. Our code is available at: https://github.com/jfc43/eval-transductive-robustness . 1 We note that this type of defense goes under different names such as "test-time adaptation" or "dynamic defenses". Nevertheless, they all fall into the classic transductive learning paradigm (Vapnik, 1998) , which attempts to leverage test data for learning. We thus call them transductive-learning based defenses. The word "transductive" is also adopted in Goldwasser et al. (2020) .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Evaluating the Adversarial Robustness of Adaptive Test-time DefensesFrancesco Croce, Sven Gowal, Thomas Brunner, Evan Shelhamer 等ICML 2022 · 被引用 85 次
- Demystifying the Adversarial Robustness of Random Transformation DefensesChawin Sitawarin, Zachary J. Golan-Strieb, David A. WagnerICML 2022 · 被引用 26 次
- Uncovering Adversarial Risks of Test-Time AdaptationTong Wu, Feiran Jia, Xiangyu Qi, Jiachen T. Wang 等ICML 2023 · 被引用 12 次
- Nearly Space-Optimal Graph and Hypergraph Sparsification in Insertion-Only Data StreamsVincent Cohen-Addad, David P. Woodruff, Shenghao Xie, Samson ZhouICLR 2026 · 被引用 2 次
- Sparsity Brings Vulnerabilities: Exploring New Metrics in Backdoor AttacksJianwen Tian, Kefan Qiu, Debin Gao, Zhi Wang 等USENIX Security 2023
它引用的顶会 Paper11
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 被引用 1,026 次
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 被引用 917 次
相关 Paper
- Two Heads are Actually Better than One: Towards Better Adversarial Robustness via Transduction and RejectionNils Palumbo, Yang Guo, Xi Wu, Jiefeng Chen 等ICML 2024
- Better Safe Than Sorry: Preventing Delusive Adversaries with Adversarial TrainingLue Tao, Lei Feng, Jinfeng Yi, Sheng-Jun Huang 等NeurIPS 2021 · 被引用 90 次
- You Don't Protect if You Don't Expect: Breaking the Key Assumption behind CLIP's Test-Time DefensesRuize Zhang, Yu Li, Zhang Wan, Juan Cao 等ICML 2026
- On the Adversarial Risk of Test Time Adaptation: An Investigation into Realistic Test-Time Data PoisoningYongyi Su, Yushu Li, Nanqing Liu, Kui Jia 等ICLR 2025
- Embracing Adaptation: An Effective Dynamic Defense Strategy Against Adversarial ExamplesShenglin Yin, Kelu Yao, Zhen Xiao, Jieyi LongACM MM 2024
