FERD: Fairness-Enhanced Data-Free Adversarial Robustness Distillation
Zhengxiao Li, Liming Lu, Xu Zheng, Si Yuan Liang, Taric Chen, Yongbin Zhou, Shuchao Pang
摘要
Data-Free Robustness Distillation (DFRD) aims to transfer the robustness from the teacher to the student without accessing the training data. While existing methods focus on overall robustness, they overlook the robust fairness issues, leading to severe disparity of robustness across different categories. In this paper, we find two key problems: (1) student model distilled with equal class proportion data behaves significantly different across distinct categories; and (2) the robustness of student model is not stable across different attacks target. To bridge these gaps, we present the first Fairness Enhanced data-free Robustness Distillation (FERD) framework to adjust the proportion and distribution of adversarial examples. For the proportion, FERD adopts a robustness guided class reweighting strategy to synthesize more samples for the less robust categories, thereby improving robustness of them. For the distribution, FERD generates complementary data samples for advanced robustness distillation. It generates Fairness-Aware Examples (FAEs) by enforcing a uniformity constraint on feature-level predictions, which suppress the dominance of class-specific non-robust features, providing a more balanced representation across all categories. Then, FERD constructs Uniform-Target Adversarial Examples (UTAEs) from FAEs by applying a uniform target class constraint to avoid biased attack directions, which distribute the attack targets across all categories and prevents overfitting to specific vulnerable categories. Extensive experiments on three public datasets demonstrate that FERD achieves state-of-the-art worst-class robustness and NSD under all adversarial attacks. For instance, FERD improves worst-class robustness by up to 11.3% and reduces NSD by 0.077 compared to the optimal baseline on CIFAR-10 with MobileNet-V2. Our code is available at: https://github.com/mayaobuduyao/FERD.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper23
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Adversarially Robust DistillationMicah Goldblum, Liam Fowl, Soheil Feizi, Tom GoldsteinAAAI 2020 · 被引用 258 次
- To be Robust or to be Fair: Towards Fairness in Adversarial TrainingHan Xu, Xiaorui Liu, Yaxin Li, Anil K. Jain 等ICML 2021 · 被引用 218 次
- Adversarial Robustness vs. Model Compression, or Both?Shaokai Ye, Xue Lin, Kaidi Xu, Sijia Liu 等ICCV 2019 · 被引用 180 次
相关 Paper
- Revisiting Adversarial Robustness Distillation from the Perspective of Robust FairnessXinli Yue, Ningping Mou, Qian Wang, Lingchen ZhaoNeurIPS 2023 · 被引用 28 次
- Improving Adversarial Robust Fairness via Anti-Bias Soft Label DistillationShiji Zhao, Ranjie Duan, Xizhe Wang, Xingxing WeiNeurIPS 2024 · 被引用 12 次
- DERD: Data-free Adversarial Robustness Distillation through Self-adversarial Teacher GroupYuhang Zhou, Yushu Zhang, Leo Yu Zhang, Zhongyun HuaACM MM 2024 · 被引用 3 次
- Impartial Adversarial Distillation: Addressing Biased Data-Free Knowledge Distillation via Adaptive Constrained OptimizationDongping Liao, Xitong Gao, Chengzhong XuAAAI 2024 · 被引用 5 次
- Towards Fairness-Aware Adversarial LearningYanghao Zhang, Tianle Zhang, Ronghui Mu, Xiaowei Huang 等CVPR 2024 · 被引用 6 次
