arXiv:2506.17874stat.MLcs.CV2025-06被引 1

将分布鲁棒优化与数据增强结合,提升模型抗干扰能力。

DRO-Augment Framework: Robustness by Synergizing Wasserstein Distributionally Robust Optimization and Data Augmentation

  • 融合Wasserstein分布鲁棒优化与多种数据增强策略
  • 在严重噪声和对抗攻击下仍保持高准确率
  • 理论证明了训练模型的泛化误差上界

在众多实际应用中,确保深度神经网络(DNN)的鲁棒性和稳定性至关重要,尤其在面对各种输入扰动的图像分类任务中。尽管数据增强技术已被广泛采用以提高模型对扰动的抵抗能力,但在同时应对数据损坏和对抗攻击方面仍有显著提升空间。为此,我们提出DRO-Augment框架,将Wasserstein分布鲁棒优化(W-DRO)与多种数据增强策略相结合,显著提升模型在广泛类型噪声下的鲁棒性。该方法在严重数据扰动和对抗攻击场景下优于现有增强方法,同时在CIFAR-10-C、CIFAR-100-C、MNIST和Fashion-MNIST等基准数据集上保持干净数据上的准确率。理论上,我们为使用计算高效的变分正则化损失函数训练的神经网络建立了新的泛化误差界,该损失函数与W-DRO问题密切相关。

原文摘要 · Abstract (English)

In many real-world applications, ensuring the robustness and stability of deep neural networks (DNNs) is crucial, particularly for image classification tasks that encounter various input perturbations. While data augmentation techniques have been widely adopted to enhance the resilience of a trained model against such perturbations, there remains significant room for improvement in robustness against corrupted data and adversarial attacks simultaneously. To address this challenge, we introduce DRO-Augment, a novel framework that integrates Wasserstein Distributionally Robust Optimization (W-DRO) with various data augmentation strategies to improve the robustness of the models significantly across a broad spectrum of corruptions. Our method outperforms existing augmentation methods under severe data perturbations and adversarial attack scenarios while maintaining the accuracy on the clean datasets on a range of benchmark datasets, including but not limited to CIFAR-10-C, CIFAR-100-C, MNIST, and Fashion-MNIST. On the theoretical side, we establish novel generalization error bounds for neural networks trained using a computationally efficient, variation-regularized loss function closely related to the W-DRO problem.

分布鲁棒数据增强对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。