发表机构
North Carolina State University(北卡罗来纳州立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出Threat Conditional Network(TCN),通过表示分解框架实现单模型跨连续威胁等级的强鲁棒性,在多数据集上性能优于或媲美专用模型集成,仅增加少量参数开销。
AI 中文摘要
对抗鲁棒模型通常会过拟合到特定的攻击预算,这使得需要为多样化和动态的对抗环境配备多个专用模型,而当威胁空间扩大时,这种策略在根本上变得难以处理。这提出了一个开放挑战:我们能否在单个模型中实现跨连续威胁等级的强鲁棒性?我们提出了威胁条件网络(Threat Conditional Network, TCN),该网络基于表示分解框架构建,将表示学习分解为威胁不变的共享骨干和轻量级的威胁条件适配器。TCN通过基于傅里叶的嵌入和通道级仿射调制,使单个模型能够根据扰动水平进行条件调整,并针对扰动预算的分布进行训练,从而在推理过程中实现跨无限连续威胁等级的灵活且无缝的适应。在CIFAR-10、CIFAR-100和Tiny-ImageNet上进行的大量实验表明,TCN仅用一组参数就可达到或超过预算专用模型的完整集成的性能,能泛化到未见过的扰动预算,并在不匹配的威胁条件下实现稳健迁移,且仅产生4.6%的参数开销。这些贡献为动态多样威胁环境中的自适应和可泛化鲁棒性指明了一条有前景的道路。
英文摘要
Adversarially robust models often overfit to a specific attack budget, necessitating multiple specialized models for diverse and dynamic adversarial environments, a strategy that becomes fundamentally intractable as the threat space grows. This raises an open challenge: can we achieve strong robustness across a continuum of threat levels within a single model? We propose the Threat Conditional Network (TCN), grounded in a representation factorization framework that decomposes representation learning into a threat-invariant shared backbone and a lightweight threat-conditional adaptor. TCN conditions a single model on the perturbation level via Fourier-based embeddings and channel-wise affine modulation, and is trained against a distribution over perturbation budgets, enabling flexible and seamless adaptation across an infinite continuum of threat levels during inference. Extensive experiments on CIFAR-10, CIFAR-100, and Tiny-ImageNet show that TCN matches or surpasses a full ensemble of budget-specialized models with a single set of parameters, generalizes to unseen perturbation budgets, and transfers robustly under mismatched threat conditions, with only 4.6\% parameter overhead. These contributions chart a promising path toward adaptive and generalizable robustness in dynamic and diverse threat environments.