Improving Adversarial Robustness via Unlabeled Out-of-Domain Data

被引:0
|
作者
Deng, Zhun [1 ]
Zhang, Linjun [2 ]
Ghorbani, Amirata [3 ]
Zou, James [3 ]
机构
[1] Harvard Univ, Cambridge, MA 02138 USA
[2] Rutgers State Univ, New Brunswick, NJ USA
[3] Stanford Univ, Stanford, CA 94305 USA
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Data augmentation by incorporating cheap unlabeled data from multiple domains is a powerful way to improve prediction especially when there is limited labeled data. In this work, we investigate how adversarial robustness can be enhanced by leveraging out-of-domain unlabeled data. We demonstrate that for broad classes of distributions and classifiers, there exists a sample complexity gap between standard and robust classification. We quantify the extent to which this gap can be bridged by leveraging unlabeled samples from a shifted domain by providing both upper and lower bounds. Moreover, we show settings where we achieve better adversarial robustness when the unlabeled data come from a shifted domain rather than the same domain as the labeled data. We also investigate how to leverage out-of-domain data when some structural information, such as sparsity, is shared between labeled and unlabeled domains. Experimentally, we augment object recognition datasets (CIFAR10, CINIC-10, and SVHN) with easy-to-obtain and unlabeled out-of-domain data and demonstrate substantial improvement in the model's robustness against `1 adversarial attacks on the original domain.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Combining in-domain and out-of-domain speech data for automatic recognition of disordered speech
    Christensen, H.
    Aniol, M. B.
    Bell, P.
    Green, P.
    Hain, T.
    King, S.
    Swietojanski, P.
    14TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION (INTERSPEECH 2013), VOLS 1-5, 2013, : 3609 - 3612
  • [42] Unsupervised Out-of-Domain Detection via Pre-trained Transformers
    Xu, Keyang
    Ren, Tongzheng
    Zhang, Shikun
    Feng, Yihao
    Xiong, Caiming
    59TH ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS AND THE 11TH INTERNATIONAL JOINT CONFERENCE ON NATURAL LANGUAGE PROCESSING, VOL 1 (ACL-IJCNLP 2021), 2021, : 1052 - 1061
  • [43] Using Representation Learning and Out-of-domain Data for a Paralinguistic Speech Task
    Milde, Benjamin
    Biemann, Chris
    16TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION (INTERSPEECH 2015), VOLS 1-5, 2015, : 904 - 908
  • [44] Improving Adversarial Robustness of Masked Autoencoders via Test-time Frequency-domain Prompting
    Huang, Qidong
    Dong, Xiaoyi
    Chen, Dongdong
    Chen, Yinpeng
    Yuan, Lu
    Hua, Gang
    Zhang, Weiming
    Yu, Nenghai
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 1600 - 1610
  • [45] Improving Adversarial Robustness via Distillation-Based Purification
    Koo, Inhwa
    Chae, Dong-Kyu
    Lee, Sang-Chul
    Cascio, Donato
    APPLIED SCIENCES-BASEL, 2023, 13 (20):
  • [46] An Adversarial Training Method for Improving Model Robustness in Unsupervised Domain Adaptation
    Nie, Zhishen
    Lin, Ying
    Yan, Meng
    Cao, Yifan
    Ning, Shengfu
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, PT III, 2021, 12817 : 3 - 13
  • [47] Improving unsupervised neural aspect extraction for online discussions using out-of-domain classification
    Alekseev, Anton
    Tutubalina, Elena
    Malykh, Valentin
    Nikolenko, Sergey
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2020, 39 (02) : 2487 - 2496
  • [48] Out-of-Domain Human Mesh Reconstruction via Dynamic Bilevel Online Adaptation
    Guan, Shanyan
    Xu, Jingwei
    He, Michelle Zhang
    Wang, Yunbo
    Ni, Bingbing
    Yang, Xiaokang
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (04) : 5070 - 5086
  • [49] Certifying Out-of-Domain Generalization for Blackbox Functions
    Weber, Maurice
    Li, Linyi
    Wang, Boxin
    Zhao, Zhikuan
    Li, Bo
    Zhang, Ce
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [50] Rewriting a Generative Model with Out-of-Domain Patterns
    Gao, Panpan
    Sun, Hanxu
    Chen, Gang
    Li, Minggang
    ELECTRONICS, 2025, 14 (04):