既非对抗训练亦非净化:由振荡预测学习涌现的对抗鲁棒性
Neither Adversarial Training Nor Purification: Emergent Adversarial Robustness from Oscillatory Predictive Learning
- Ecole polytechnique(巴黎综合理工学院)
- Ecole Nationale des Ponts et Chaussées(巴黎国立路桥学校)
- Mohamed bin Zayed University of Artificial Intelligence(穆罕默德·本·扎耶德人工智能大学)
- Okinawa Institute of Science and Technology(冲绳科学技术大学院大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
提出振荡预测学习框架,通过结合人工藏本振荡神经元与预测性自监督预训练,无需对抗训练或净化,在CIFAR-10和CIFAR-100上实现了具有竞争力的对抗鲁棒性。
AI中文摘要:
计算机视觉中的对抗鲁棒性目前仍主要通过对抗训练或测试时对抗净化实现,这两种方法都会在训练时生成对抗样本或在测试时进行迭代去噪,从而引入显著的计算开销。我们研究经验鲁棒性是否能够转而从架构和表示学习的归纳偏置中涌现。我们提出振荡预测学习(OPL),这是一个两阶段框架,将人工藏本振荡神经元(AKOrN)与使用X-PhiNet的预测性自监督预训练相结合。由于我们的默认检查点使用随机初始化的振荡器状态,我们将其与其他随机化对抗防御方法进行比较,这些方法提供了精确、可复现且强大的攻击协议。在CIFAR-10和CIFAR-100上的实验,以及在CIFAR-10-C上的额外损坏评估,表明我们的方法在AutoAttack-rand评估协议下取得了具有竞争力的结果。在CIFAR-10和CIFAR-100上,OPL在ℓ∞,ε=8/255,EoT K=20的AutoAttack-rand下分别达到了76.63±0.76%和50.44%的鲁棒准确率。
英文摘要:
Adversarial robustness in computer vision is still largely achieved through adversarial training or test-time adversarial purification, both of which introduce significant computational overhead by generating adversarial examples during training or performing iterative denoising at test time. We study whether empirical robustness can instead emerge from architectural and representation-learning inductive biases. We introduce Oscillatory Predictive Learning (OPL), a two-stage framework that combines Artificial Kuramoto Oscillatory Neurons (AKOrN) with predictive self-supervised pretraining using X-PhiNet. Because our default checkpoint uses randomized initial oscillator states, we compare it with other randomized adversarial defense methods that provide precise, reproducible, and strong attack protocols. Experiments on CIFAR-10 and CIFAR-100, with additional corruption evaluation on CIFAR-10-C, demonstrate that our method achieves competitive results under the AutoAttack-rand evaluation protocol. On CIFAR-10 and CIFAR-100, OPL attains 76.63$\pm$0.76$\%$ and 50.44$\%$ robust accuracy, respectively, under $\ell_\infty$, $ε=8/255$, AutoAttack-rand with EoT $K=20$.