Improving Sustainability of Adversarial Examples in Class-Incremental Learning
Taifeng Liu, Xinjing Liu, Liangqiu Dong, Yang Liu, Yilong Yang, Zhuo Ma
摘要
Current adversarial examples (AEs) are typically designed for static models. However, with the wide application of Class-Incremental Learning (CIL), models are no longer static and need to be updated with new data distributed and labeled differently from the old ones. As a result, existing AEs often fail after CIL updates due to significant domain drift. In this paper, we propose SAE to enhance the sustainability of AEs against CIL. The core idea of SAE is to enhance the robustness of AE semantics against domain drift by making them more similar to the target class while distinguishing them from all other classes. Achieving this is challenging, as relying solely on the initial CIL model to optimize AE semantics often leads to overfitting. To resolve the problem, we propose a Semantic Correction Module. This module encourages the AE semantics to be generalized, based on a visual-language model capable of producing universal semantics. Additionally, it incorporates the CIL model to correct the optimization direction of the AE semantics, guiding them closer to the target class. To further reduce fluctuations in AE semantics, we propose a Filtering-and-Augmentation Module, which first identifies non-target examples with target-class semantics in the latent space and then augments them to foster more stable semantics. Comprehensive experiments demonstrate that SAE outperforms baselines by an average of 31.28% when updated with a 9-fold increase in the number of classes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper18
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh 等ICML 2021 · 被引用 47,906 次
- Dark Experience for General Continual Learning: a Strong, Simple BaselinePietro Buzzega, Matteo Boschini, Angelo Porrello, Davide Abati 等NeurIPS 2020 · 被引用 1,494 次
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 被引用 1,295 次
- Learning to Prompt for Continual LearningZifeng Wang, Zizhao Zhang, Chen-Yu Lee, Han Zhang 等CVPR 2022 · 被引用 635 次
- RMM: Reinforced Memory Management for Class-Incremental LearningYaoyao Liu, Bernt Schiele, Qianru SunNeurIPS 2021 · 被引用 125 次
相关 Paper
- Bring Evanescent Representations to Life in Lifelong Class Incremental LearningMarco Toldo, Mete OzayCVPR 2022 · 被引用 34 次
- Expandable Subspace Ensemble for Pre-Trained Model-Based Class-Incremental LearningDa-Wei Zhou, Hai-Long Sun, Han-Jia Ye, De-Chuan ZhanCVPR 2024
- Attacks on Continual Semantic Segmentation by Perturbing Incremental SamplesZhidong Yu, Wei Yang, Xike Xie, Zhenbo ShiAAAI 2024 · 被引用 1 次
- XIL: Cross-Expanding Incremental LearningHeayoun Choi, Hyundong Jin, Eunwoo KimICLR 2026
- Navigating Semantic Drift in Task-Agnostic Class-Incremental LearningFangwen Wu, Lechao Cheng, Shengeng Tang, Xiaofeng Zhu 等ICML 2025
