对比了自监督与监督模型在对抗攻击下的表现,发现自监督更鲁棒但效果随任务变化。
Adversarial Robustness of Discriminative Self-Supervised Learning in Vision
- 对比7种自监督与1种监督模型的抗干扰能力
- 自监督在图像分类中更抗攻击,迁移学习中优势仍存
- 微调或复杂任务下优势减弱,适合关注模型安全的研究者
自监督学习(SSL)在视觉表征学习中已取得显著进展,但其对抗鲁棒性的系统评估仍不充分。本文评估了七种判别式自监督模型和一种监督模型在多种任务中的表现,包括ImageNet分类、迁移学习、分割和检测。结果表明,判别式自监督模型在ImageNet分类任务上普遍比监督模型更具对抗鲁棒性,且该优势在使用线性评估的迁移学习中依然存在。然而,在微调后,自监督与监督模型之间的鲁棒性差距明显缩小;在分割和检测任务中,这种优势也基本消失。此外,我们还研究了架构选择、训练时长、数据增强和批大小等因素对对抗鲁棒性的影响。本研究为理解视觉自监督表示系统的对抗安全性提供了实证支持。
原文摘要 · Abstract (English)
Self-supervised learning (SSL) has advanced significantly in visual representation learning, yet comprehensive evaluations of its adversarial robustness remain limited. In this study, we evaluate the adversarial robustness of seven discriminative self-supervised models and one supervised model across diverse tasks, including ImageNet classification, transfer learning, segmentation, and detection. Our findings suggest that discriminative SSL models generally exhibit better robustness to adversarial attacks compared to their supervised counterpart on ImageNet, with this advantage extending to transfer learning when using linear evaluation. However, when fine-tuning is applied, the robustness gap between SSL and supervised models narrows considerably. Similarly, this robustness advantage diminishes in segmentation and detection tasks. We also investigate how various factors might influence adversarial robustness, including architectural choices, training duration, data augmentations, and batch sizes. Our analysis contributes to the ongoing exploration of adversarial robustness in visual self-supervised representation systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。