English

Mind Your Margin and Boundary: Are Your Distilled Datasets Truly Robust?

Computer Vision and Pattern Recognition 2026-05-27 v2

Abstract

Dataset distillation (DD) compresses a large training set into a small synthetic set for efficient training, but most DD methods optimize only clean accuracy and leave robustness uncontrolled. Recent robust DD methods improve robustness, yet they often suffer from a poor accuracy-robustness trade-off because they (i) treat all adversarially perturbed examples uniformly, despite robust risk being dominated by near-zero robust margins, and (ii) do not explicitly increase inter-class separation in the decision boundary where attacks concentrate. We present Contrastive Curriculum for Robust Dataset Distillation (C2^2R), a framework that couples an attack-aware curriculum with a contrastive robustness objective. From a robust-margin perspective, we derive a perturbation score that approximates each sample's robust hinge, enabling a curriculum that prioritizes the smallest-margin adversaries that most directly drive robust error. In parallel, a class-balanced contrastive robustness loss enforces adversarial invariance while explicitly widening boundary separation across classes. Experiments on CIFAR-10/100, Tiny-ImageNet, and multiple ImageNet-1K subsets under six attacks show that C2^2R achieves the best robust accuracy, outperforming prior robust DD by 2.82.8% on average.

Keywords

Cite

@article{arxiv.2605.20606,
  title  = {Mind Your Margin and Boundary: Are Your Distilled Datasets Truly Robust?},
  author = {Muquan Li and Yingyi Ma and Yihong Huang and Hang Gou and Ke Qin and Ming Li and Yuan-Fang Li and Tao He},
  journal= {arXiv preprint arXiv:2605.20606},
  year   = {2026}
}

Comments

Accepted to ICML 2026

R2 v1 2026-07-22T07:23:01.941Z