通过几何结构设计提升模型鲁棒性,让特征空间自动过滤噪声和对抗攻击。
CCAR: Intrinsic Robustness as an Emergent Geometric Property

- 引入类条件激活正则化,强制特征在正交子空间中分布
- 在标签噪声和输入扰动下,性能显著优于基线方法
- 理论证明几何解耦可提升算法稳定性,适合安全敏感场景
标准监督学习优化预测准确率,但对学习到的特征内部几何结构不加干预,常导致特征纠缠且脆弱。我们提出类条件激活正则化(CCAR),通过软归纳偏置显式构造特征空间,强制其呈现块对角结构。通过将类别能量限制在正交子空间内,构建出能自然抑制噪声与对抗扰动的内在几何框架。理论上,该结构约束与最大化Fisher判别比相关联,建立了几何解耦与算法稳定性的正式联系。实验证明,鲁棒性是良好设计特征空间的涌现属性,在标签噪声和输入破坏基准上显著超越基线方法。
原文摘要 · Abstract (English)
Standard supervised learning optimizes for predictive accuracy but remains agnostic to the internal geometry of learned features, often yielding representations that are entangled and brittle. We propose Class-Conditional Activation Regularization (CCAR) to explicitly engineer the feature space, imposing a block-diagonal structure via a soft inductive bias. By shaping the latent representation to confine class energy to orthogonal subspaces, we create an intrinsic geometric scaffold that naturally filters noise and adversarial perturbations. We provide theoretical analysis linking this structural constraint to the maximization of the Fisher Discriminant Ratio, establishing a formal connection between geometric disentanglement and algorithmic stability. Empirically, this approach demonstrates that robustness is an emergent property of a well-engineered feature space, significantly outperforming baselines on label noise and input corruption benchmarks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。