DD-RobustBench:面向数据集蒸馏的对抗鲁棒性基准
计算机视觉与模式识别
2024-10-15 v3
摘要
数据集蒸馏是一种旨在将数据集压缩成显著更小版本,同时保持强大训练性能的先进技术。已有大量工作致力于在有限压缩比下提高评估准确性,但忽视了蒸馏数据集的鲁棒性。在这项工作中,我们引入了一个全面的基准,据我们所知,这是迄今为止在以统一方式评估蒸馏数据集对抗鲁棒性方面最广泛的基准。我们的基准显著扩展了先前的工作,纳入了更广泛的数据集蒸馏方法,包括最新的进展如TESLA和SRe2L,多样化的对抗攻击方法,以及在更广泛和更大量的数据集(如ImageNet-1K)上的评估。此外,我们评估了这些蒸馏数据集针对代表性对抗攻击算法(如PGD和AutoAttack)的鲁棒性,同时从频率角度探索了它们的弹性。我们还发现,将蒸馏数据纳入原始数据集的训练批次中可以提高鲁棒性。
引用
@article{arxiv.2403.13322,
title = {DD-RobustBench: An Adversarial Robustness Benchmark for Dataset Distillation},
author = {Yifan Wu and Jiawei Du and Ping Liu and Yuewei Lin and Wei Xu and Wenqing Cheng},
journal= {arXiv preprint arXiv:2403.13322},
year = {2024}
}
备注
* denotes equal contributions; ^ denotes corresponding author. In this updated version, we have expanded our research to include more experiments on various adversarial attack methods and latest dataset distillation studies. All new results have been incorporated into the document