为视觉语言模型提供语义扰动下的鲁棒性认证方法
Semantic Robustness Certification for Vision-Language Models

- 用文本提示作为语义代理,控制变化程度
- 可定量证明在一定语义变化下预测不变
- 无需额外数据,适合真实场景应用
视觉语言模型(VLMs)广泛应用于下游任务,但现实应用中常面临由语义变化(如形状、大小、风格)引起的分布偏移。鲁棒性认证旨在判断输入变换后模型预测是否改变。现有框架多关注几何或像素级变换,本文提出首个针对语义级变换的鲁棒性认证框架。利用VLM的开放词汇能力,我们以文本提示作为语义代理,构建由程度参数控制的变换。通过闭式刻画VLM决策边界,该框架可量化认证预测类别保持不变的语义变化区间。该方法无需为每种变化收集额外数据,具有实际可操作性。在合成与真实数据上的实验表明,该框架能有效认证多种语义变化下的鲁棒性。
原文摘要 · Abstract (English)
Vision-language models (VLMs) are now widely used in downstream tasks. However, real-world applications often expose VLMs to distribution shifts induced by semantic variation (e.g., shape, size, and style). Robustness certification determines if a model's prediction changes when transformations are applied to its input. While most certification frameworks study geometric or pixel-level transformations over inputs, this work proposes a novel framework that enables certifying VLM robustness under semantic-level transformations. Leveraging the open-vocabulary capability of VLMs, we use text prompts as semantic proxies to construct transformations parameterized by an extent that controls the degree of semantic variation. By characterizing the VLM decision boundary in closed form, our framework quantitatively certifies extent intervals for which the predicted class remains unchanged under the semantic transformation. Our framework is the first to certify VLM robustness under semantic-level variations without requiring additional data for each variation, making it practical to apply. Experiments on both synthetic and real-world data show that our framework enables certifying robustness under diverse semantic variations across scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。