用超网络+区间传播实现可认证鲁棒的持续学习
SHIELD: Secure Hypernetworks for Incremental Expansion Learning Defense
- 通过共享超网络生成任务专属参数,无需存储历史数据
- 在强白盒攻击下平均准确率领先,且保持高效扩展性
- 适合需要理论保障的高安全场景持续学习
在对抗性条件下进行持续学习仍是未解难题,现有方法常牺牲鲁棒性或可扩展性。本文提出SHIELD框架,将区间边界传播(IBP)与基于超网络的架构结合,实现跨序列任务的可认证鲁棒持续学习。该方法通过仅依赖紧凑任务嵌入的共享超网络生成特定任务模型参数,避免了重放缓冲区或完整模型副本,支持高效增量更新。为增强鲁棒性,引入区间MixUp训练策略,以ℓ∞球形式混合虚拟样本,利用区间算术保证认证鲁棒性并缓解包裹效应,获得更平滑决策边界。在多个基准上评估,面对PGD和AutoAttack等强白盒攻击,SHIELD持续优于现有鲁棒持续学习方法,在保持可扩展性和认证能力的同时,达到当前最优平均准确率。结果标志着对抗环境下实用且理论严谨的持续学习迈出关键一步。
原文摘要 · Abstract (English)
Continual learning under adversarial conditions remains an open problem, as existing methods often compromise either robustness, scalability, or both. We propose a novel framework that integrates Interval Bound Propagation (IBP) with a hypernetwork-based architecture to enable certifiably robust continual learning across sequential tasks. Our method, SHIELD, generates task-specific model parameters via a shared hypernetwork conditioned solely on compact task embeddings, eliminating the need for replay buffers or full model copies and enabling efficient over time. To further enhance robustness, we introduce Interval MixUp, a novel training strategy that blends virtual examples represented as $\ell_{\infty}$ balls centered around MixUp points. Leveraging interval arithmetic, this technique guarantees certified robustness while mitigating the wrapping effect, resulting in smoother decision boundaries. We evaluate SHIELD under strong white-box adversarial attacks, including PGD and AutoAttack, across multiple benchmarks. It consistently outperforms existing robust continual learning methods, achieving state-of-the-art average accuracy while maintaining both scalability and certification. These results represent a significant step toward practical and theoretically grounded continual learning in adversarial settings.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。