Adversarial Self-Training Improves Robustness and Generalization for Gradual Domain Adaptation
Lianghe Shi, Weiwei Liu
摘要
Gradual Domain Adaptation (GDA), in which the learner is provided with additional intermediate domains, has been theoretically and empirically studied in many contexts. Despite its vital role in security-critical scenarios, the adversarial robustness of the GDA model remains unexplored. In this paper, we adopt the effective gradual self-training method and replace vanilla self-training with adversarial self-training (AST). AST first predicts labels on the unlabeled data and then adversarially trains the model on the pseudo-labeled distribution. Intriguingly, we find that gradual AST improves not only adversarial accuracy but also clean accuracy on the target domain. We reveal that this is because adversarial training (AT) performs better than standard training when the pseudo-labels contain a portion of incorrect labels. Accordingly, we first present the generalization error bounds for gradual AST in a multiclass classification setting. We then use the optimal value of the Subset Sum Problem to bridge the standard error on a real distribution and the adversarial error on a pseudo-labeled distribution. The result indicates that AT may obtain a tighter bound than standard training on data with incorrect pseudo-labels. We further present an example of a conditional Gaussian distribution to provide more insights into why gradual AST can improve the clean accuracy for GDA.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper11
- Samba: Severity-aware Recurrent Modeling for Cross-domain Medical Image GradingQi Bi, Jingjun Yi, Hao Zheng, Wei Ji 等NeurIPS 2024 · 被引用 10 次
- A Closer Look at Curriculum Adversarial Training: From an Online PerspectiveLianghe Shi, Weiwei LiuAAAI 2024 · 被引用 7 次
- Bayesian Domain Adaptation with Gaussian Mixture Domain-IndexingYanfang Ling, Jiyong Li, Lingbo Li, Shangsong LiangNeurIPS 2024 · 被引用 7 次
- DRF: Improving Certified Robustness via Distributional Robustness FrameworkZekai Wang, Zhengyu Zhou, Weiwei LiuAAAI 2024 · 被引用 7 次
- A Provable Decision Rule for Out-of-Distribution DetectionXinsong Ma, Xin Zou, Weiwei LiuICML 2024 · 被引用 4 次
它引用的顶会 Paper15
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- FixMatch: Simplifying Semi-Supervised Learning with Consistency and ConfidenceKihyuk Sohn, David Berthelot, Nicholas Carlini, Zizhao Zhang 等NeurIPS 2020 · 被引用 5,129 次
- Confidence Regularized Self-TrainingYang Zou, Zhiding Yu, Xiaofeng Liu, B. V. K. Vijaya Kumar 等ICCV 2019 · 被引用 901 次
- Do Adversarially Robust ImageNet Models Transfer Better?Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor 等NeurIPS 2020 · 被引用 506 次
- Attacks Which Do Not Kill Training Make Adversarial Learning StrongerJingfeng Zhang, Xilie Xu, Bo Han, Gang Niu 等ICML 2020 · 被引用 452 次
相关 Paper
- Self-Training with Dynamic Weighting for Robust Gradual Domain AdaptationZixi Wang, Yushe Cao, Yubo Huang, Jinzhu Wei 等NeurIPS 2025 · 被引用 3 次
- Understanding Gradual Domain Adaptation: Improved Analysis, Optimal Path and BeyondHaoxiang Wang, Bo Li, Han ZhaoICML 2022 · 被引用 48 次
- SRoUDA: Meta Self-Training for Robust Unsupervised Domain AdaptationWanqing Zhu, Jia-Li Yin, Bo-Hao Chen, Ximeng LiuAAAI 2023 · 被引用 14 次
- Toward Improving Robustness and Accuracy in Unsupervised Domain AdaptationAishwarya Soni, Tanima DuttaAAAI 2025 · 被引用 3 次
- Adversarial-Learned Loss for Domain AdaptationMinghao Chen, Shuai Zhao, Haifeng Liu, Deng CaiAAAI 2020 · 被引用 195 次
