Feature Collapse Under Corruption: An Entropy Perspective on Robust Neural Networks
Vishesh Kumar, Akshay Agarwal
摘要
Even after decades of advances in neural network training, the inherent robustness challenge remains open. While the sensitivity to adversarial perturbations is understandable given their intentional learning, the most surprising fact is the vulnerability to natural corruptions. Surprisingly, not only is the cause of this inherent vulnerability unknown, but the concern extends beyond traditional CNNs; it also applies to current models, including transformers and large foundation models. For the first time, through this work, we observe that natural corruptions often collapse the network's internal feature space into a high-entropy state, causing predictions to rely on a small subset of fragile features. Inspired by this, we propose a simple yet effective entropy-guided fine-tuning framework, Dem-HEC, that strengthens corruption robustness while maintaining clean accuracy. Our method generates high-entropy samples within a bounded perturbation region and repairs the model using both clean and high-entropy samples. We further combine this objective with distilling knowledge from a teacher snapshot to maintain stable predictions. The proposed Dem-HEC is effective across datasets ranging from small to large-resolution, from pure CNNs to transformers, and to large foundation models, including DinoV3. The proposed approach outperforms the state-of-the-art (SOTA) models not only in improving robustness but also in retaining or boosting clean accuracy.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- TrivialAugment: Tuning-free Yet State-of-the-Art Data AugmentationSamuel G. Müller, Frank HutterICCV 2021 · 被引用 384 次
- AugMax: Adversarial Composition of Random Augmentations for Robust TrainingHaotao Wang, Chaowei Xiao, Jean Kossaifi, Zhiding Yu 等NeurIPS 2021 · 被引用 153 次
- Measuring Robustness in Deep Learning Based Compressive SensingMohammad Zalbagi Darestani, Akshay S. Chaudhari, Reinhard HeckelICML 2021 · 被引用 94 次
- IPMix: Label-Preserving Data Augmentation Method for Training Robust ClassifiersZhenglin Huang, Xiaoan Bao, Na Zhang, Qingqi Zhang 等NeurIPS 2023 · 被引用 26 次
- Democratic Training Against Universal Adversarial PerturbationsBing Sun, Jun Sun, Wei ZhaoICLR 2025
相关 Paper
- Improving Robustness of Vision Transformers by Reducing Sensitivity to Patch CorruptionsYong Guo, David Stutz, Bernt SchieleCVPR 2023
- Maximum-Entropy Adversarial Data Augmentation for Improved Generalization and RobustnessLong Zhao, Ting Liu, Xi Peng, Dimitris N. MetaxasNeurIPS 2020 · 被引用 207 次
- MetaRepair: Learning to Repair Deep Neural Networks from Repairing ExperiencesYun Xing, Qing Guo, Xiaofeng Cao, Ivor W. Tsang 等ACM MM 2024 · 被引用 5 次
- Revisiting Unnaturalness for Automated Program Repair in the Era of Large Language ModelsAidan Z. H. Yang, Sophia Kolak, Vincent J. Hellendoorn, Ruben Martins 等ICSE 2025 · 被引用 2 次
- Mitigating Feature Gap for Adversarial Robustness by Feature DisentanglementNuoyan Zhou, Dawei Zhou, Decheng Liu, Nannan Wang 等AAAI 2025 · 被引用 3 次
