arXiv:2605.02183cs.LG2026-05中稿 · IJCAI

通过几何约束提升长尾数据下的对抗鲁棒性

Manifold-Constrained Adversarial Training for Long-Tailed Robustness via Geometric Alignment

论文配图:Manifold-Constrained Adversarial Training for Long-Tailed Robustness via Geometric Alignment
图 1 · 摘自论文原文
  • 在特征空间中约束对抗样本的语义有效性,避免偏离类别流形
  • 使各类别间几何分离更均衡,显著降低尾部类别的鲁棒误差
  • 适合关注长尾分布下模型鲁棒性的研究者和工业应用

对抗训练在平衡数据集上有效,但在长尾分布下鲁棒性下降,尾部类别出现高鲁棒误差和不稳定的决策边界。本文提出流形约束对抗训练(MCAT),通过惩罚特征空间中对抗样本偏离类别条件流形的程度,确保其语义合理性,并利用受ETF启发的正则化促进各类别间的均衡几何分离。理论分析表明,几何分离可带来对抗鲁棒边界的下界,且流形约束的对抗风险在高密度语义区域上可上界鲁棒风险。在标准长尾基准上的大量实验显示,该方法在整体、均衡及尾部类别对抗鲁棒性上均实现持续提升。

原文摘要 · Abstract (English)

Adversarial training is effective on balanced datasets, but its robustness degrades under longtailed class distributions, where tail classes suffer high robust error and unstable decision boundaries. We propose Manifold-Constrained Adversarial Training (MCAT), a unified framework that enforces the semantic validity of adversarial examples by penalizing deviations from class-conditional manifolds in feature space, while promoting balanced geometric separation across classes via an ETF-inspired regularization. We provide theoretical results that link geometric separation to lower bounds on adversarially robust margins, and show that manifold-constrained adversarial risk upperbounds robust risk on high-density semantic regions. Extensive experiments on standard longtailed benchmarks demonstrate consistent improvements in overall, balanced, and tail-class adversarial robustness.

对抗训练长尾分布几何约束鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。