Robust long-tailed recognition with distribution-aware adversarial example generation

被引:0
|
作者
Li, Bo [1 ]
Yao, Yongqiang [2 ]
Tan, Jingru [3 ]
Zhu, Dandan [4 ]
Gong, Ruihao [2 ]
Luo, Ye [1 ]
Lu, Jianwei [5 ]
机构
[1] Tongji Univ, 4800 Caoan Rd, Shanghai 201804, Peoples R China
[2] Sensetime Res, 1900 Hongmei Rd, Shanghai 201103, Peoples R China
[3] Cent South Univ, 932 South Lushan Rd, Changsha 410083, Hunan, Peoples R China
[4] East China Normal Univ, 3663, Zhongshan North Rd, Shanghai 200333, Peoples R China
[5] Shanghai Univ Tradit Chinese Med, 530 Lingling Rd, Shanghai 201203, Peoples R China
关键词
Long-tailed recognition; Adversarial robustness; Distribution-aware learning; Adversarial example generation;
D O I
10.1016/j.neunet.2024.106932
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Confronting adversarial attacks and data imbalances, attaining adversarial robustness under long-tailed distribution presents a challenging problem. Adversarial training (AT) is a conventional solution for enhancing adversarial robustness, which generates adversarial examples (AEs) in a generation phase and subsequently trains on these AEs in a training phase. Existing long-tailed adversarial learning methods follow the AT framework and rebalance the AE classification in the training phase. However, few of them realize the impact of the long-tailed distribution on the generation phase. In this paper, we delve into the generation phase and uncover its imbalance across different classes. We evaluate the generation quality for different classes by comparing the differences between their generated AEs and natural examples. Our findings reveal that these differences are less pronounced in tail classes compared to head classes, indicating their inferior generation quality. To solve this problem, we propose the novel Distribution-Aware Adversarial Example Generation (DAG) method, which balances the AE generation for different classes using a Virtual Example Creator (VEC) and a Gradient-Guided Calibrator (GGC). The VEC creates virtual examples to introduce more adversarial perturbations for different classes, while the GGC calibrates the creation process to enhance the focus on tail classes based on their generation quality, effectively addressing the imbalance problem. Extensive experiments on three long-tailed adversarial benchmarks across five attack scenarios demonstrate DAG's effectiveness. On CIFAR-100-LT, DAG outperforms the previous RoBal by 4.0 points under the projected gradient descent (PGD) attack, highlighting its superiority in adversarial scenarios.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Adversarial Robustness under Long-Tailed Distribution
    Wu, Tong
    Liu, Ziwei
    Huang, Qingqiu
    Wang, Yu
    Lin, Dahua
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 8655 - 8664
  • [2] Margin-aware rectified augmentation for long-tailed recognition
    Xiang, Liuyu
    Han, Jungong
    Ding, Guiguang
    PATTERN RECOGNITION, 2023, 141
  • [3] Disentangling Label Distribution for Long-tailed Visual Recognition
    Hong, Youngkyu
    Han, Seungju
    Choi, Kwanghee
    Seo, Seokjun
    Kim, Beomsu
    Chang, Buru
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 6622 - 6632
  • [4] Breadcrumbs: Adversarial Class-Balanced Sampling for Long-Tailed Recognition
    Liu, Bo
    Li, Haoxiang
    Kang, Hao
    Hua, Gang
    Vasconcelos, Nuno
    COMPUTER VISION, ECCV 2022, PT XXIV, 2022, 13684 : 637 - 653
  • [5] Beyond the Label Distribution Prior for Long-Tailed Recognition
    Li, Ming
    Cao, Liujuan
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, ICIC 2023, PT IV, 2023, 14089 : 792 - 803
  • [6] Label-Aware Distribution Calibration for Long-Tailed Classification
    Wang, Chaozheng
    Gao, Shuzheng
    Wang, Pengyun
    Gao, Cuiyun
    Pei, Wenjie
    Pan, Lujia
    Xu, Zenglin
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, 35 (05) : 6963 - 6975
  • [7] Towards better long-tailed oracle character recognition with adversarial data augmentation
    Li, Jing
    Wang, Qiu-Feng
    Huang, Kaizhu
    Yang, Xi
    Zhang, Rui
    Goulermas, John Y.
    PATTERN RECOGNITION, 2023, 140
  • [8] Virtual Student Distribution Knowledge Distillation for Long-Tailed Recognition
    Liu, Haodong
    Huang, Xinlei
    Tang, Jialiang
    Jiang, Ning
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2024, PT IV, 2025, 15034 : 406 - 419
  • [9] Long-tailed Distribution Adaptation
    Peng, Zhiliang
    Huang, Wei
    Guo, Zonghao
    Zhang, Xiaosong
    Jiao, Jianbin
    Ye, Qixiang
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 3275 - 3282
  • [10] Distribution-aware fairness test generation
    Rajan, Sai Sathiesh
    Soremekun, Ezekiel
    Le Traon, Yves
    Chattopadhyay, Sudipta
    JOURNAL OF SYSTEMS AND SOFTWARE, 2024, 215