arXiv:2503.16975cs.CV2025-03

EasyRobust工具包提升视觉模型对抗与自然分布下的鲁棒性。

EasyRobust: A Comprehensive and Easy-to-use Toolkit for Robust and Generalized Vision

  • 集成对抗与非对抗鲁棒性训练评估一体化
  • 在图像分类任务上提供精准鲁棒性评测
  • 适合研究者与工程师快速构建可靠视觉模型

深度神经网络(DNN)在计算机视觉任务中展现出巨大潜力,但其机器视觉性能远不如人类感知。对抗攻击和数据分布偏移是导致模型性能下降、阻碍机器在真实场景中广泛应用的两大主要问题。为突破这些障碍并推动模型鲁棒性研究,我们开发了EasyRobust——一个全面且易用的视觉鲁棒性训练、评估与分析工具包。该工具包聚焦两类鲁棒性:1)对抗鲁棒性,使模型能抵御由最坏情况扰动生成的对抗样本;2)非对抗鲁棒性,提升模型在含噪声或分布偏移的自然测试图像上的表现。通过在图像分类任务上的全面基准测试,EasyRobust可实现对视觉模型鲁棒性的准确评估。我们希望EasyRobust能助力训练具备实际鲁棒性的模型,并推动学术与工业界在缩小人机视觉差距方面取得进展。代码与模型已开源:https://github.com/alibaba/easyrobust。

原文摘要 · Abstract (English)

Deep neural networks (DNNs) has shown great promise in computer vision tasks. However, machine vision achieved by DNNs cannot be as robust as human perception. Adversarial attacks and data distribution shifts have been known as two major scenarios which degrade machine performance and obstacle the wide deployment of machines "in the wild". In order to break these obstructions and facilitate the research of model robustness, we develop EasyRobust, a comprehensive and easy-to-use toolkit for training, evaluation and analysis of robust vision models. EasyRobust targets at two types of robustness: 1) Adversarial robustness enables the model to defense against malicious inputs crafted by worst-case perturbations, also known as adversarial examples; 2) Non-adversarial robustness enhances the model performance on natural test images with corruptions or distribution shifts. Thorough benchmarks on image classification enable EasyRobust to provide an accurate robustness evaluation on vision models. We wish our EasyRobust can help for training practically-robust models and promote academic and industrial progress in closing the gap between human and machine vision. Codes and models of EasyRobust have been open-sourced in https://github.com/alibaba/easyrobust.

视觉鲁棒性对抗攻击工具包

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。