arXiv:2511.11009cs.LGcs.CV2025-11IJCV被引 7

提出首个无监督鲁棒域适应框架,兼顾迁移能力与抗攻击性。

Unsupervised Robust Domain Adaptation: Paradigm, Theory and Algorithm

  • 分离对抗鲁棒性训练,分两步实现模型迁移与抗扰动。
  • 在四个数据集上验证,既保持域适应性能又显著提升抗攻击能力。
  • 首次建立鲁棒域适应理论框架,揭示传统方法失效根源。

无监督域适应(UDA)旨在通过缓解域偏移,将标签丰富的源域知识迁移到无标签目标域。现有方法多关注迁移能力,却忽视对抗攻击下的鲁棒性。尽管原始对抗训练(VAT)能提升深度网络的鲁棒性,但在UDA中效果有限。本文聚焦三个核心问题:1)为何VAT在UDA范式下失效?2)受攻击场景下的泛化界理论如何演化?3)能否无需复杂修改实现鲁棒性增强?我们揭示了通用UDA+VAT范式中的内在纠缠难题,提出无监督鲁棒域适应(URDA)新范式,并推导其泛化界,使其同时抵抗对抗噪声与域偏移。这是首次建立该范式与理论。进一步提出简单高效的算法DART——先预训练任意UDA模型,再通过解耦蒸馏实现瞬时鲁棒性增强。在四个基准数据集上,无论有无攻击,DART均有效提升鲁棒性且保持域适应能力,验证了URDA范式与理论的有效性。

原文摘要 · Abstract (English)

Unsupervised domain adaptation (UDA) aims to transfer knowledge from a label-rich source domain to an unlabeled target domain by addressing domain shifts. Most UDA approaches emphasize transfer ability, but often overlook robustness against adversarial attacks. Although vanilla adversarial training (VAT) improves the robustness of deep neural networks, it has little effect on UDA. This paper focuses on answering three key questions: 1) Why does VAT, known for its defensive effectiveness, fail in the UDA paradigm? 2) What is the generalization bound theory under attacks and how does it evolve from classical UDA theory? 3) How can we implement a robustification training procedure without complex modifications? Specifically, we explore and reveal the inherent entanglement challenge in general UDA+VAT paradigm, and propose an unsupervised robust domain adaptation (URDA) paradigm. We further derive the generalization bound theory of the URDA paradigm so that it can resist adversarial noise and domain shift. To the best of our knowledge, this is the first time to establish the URDA paradigm and theory. We further introduce a simple, novel yet effective URDA algorithm called Disentangled Adversarial Robustness Training (DART), a two-step training procedure that ensures both transferability and robustness. DART first pre-trains an arbitrary UDA model, and then applies an instantaneous robustification post-training step via disentangled distillation.Experiments on four benchmark datasets with/without attacks show that DART effectively enhances robustness while maintaining domain adaptability, and validate the URDA paradigm and theory.

域适应鲁棒性对抗训练无监督学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。