arXiv:2606.22351cs.LGcs.AI2026-06

提出抗干扰的测试时自适应方法,提升模型在恶意数据下的稳定性。

Reliability-Guided Adaptive Ensembling for Robust Test-Time Adaptation

论文配图:Reliability-Guided Adaptive Ensembling for Robust Test-Time Adaptation
图 1 · 摘自论文原文
  • 基于可靠性引导的随机增强与聚合预测,替代脆弱单视图输出。
  • 在多种攻击率下显著提升模型对对抗样本的鲁棒性,同时保持良好干净性能。
  • 适合需要高可靠性的实际部署场景,如自动驾驶、医疗诊断等。

测试时自适应(TTA)可在无需源数据的情况下缓解分布偏移,但在对抗性污染的测试流下表现脆弱,因异常输入会破坏在线更新。本文研究对抗性测试流下的鲁棒测试时自适应(RTTA),提出SAFER(Stochastic Augmentation Framework for Enhanced Robustness),一种无需训练的可靠性引导增强封装器。SAFER在不改变原有TTA目标的前提下,将易受攻击的单视图预测替换为可靠性引导的融合预测器。对每个测试样本,生成随机增强,并通过相关性加权池化结合异常检测机制聚合预测结果。进一步提出自适应混合扩展,利用特征不一致信号动态调整原始输入与增强版本的权重,以更好保留干净性能。在PACS、VLCS、OfficeHome数据集上,针对PGD攻击在不同攻击率下的评估显示,SAFER显著提升了现有TTA方法对对抗攻击的鲁棒性,同时保持了具有竞争力的干净性能。

原文摘要 · Abstract (English)

Test-time adaptation (TTA) can mitigate domain shift without source data, but it is highly brittle under adversarially contaminated test streams, where corrupted inputs also destabilize online updates. We study robust test-time adaptation (RTTA) in the adversarial-stream setting, which remains comparatively underexplored relative to standard TTA, and propose SAFER (Stochastic Augmentation Framework for Enhanced Robustness), a training-free reliability-guided augmentation wrapper for RTTA. SAFER preserves the wrapped TTA objective while replacing brittle single-view predictions with a reliability-guided pooled predictor. For each test sample, SAFER generates stochastic augmentations and aggregates their predictions through correlation-weighted pooling with outlier detection. We further study an adaptive-mixing extension that improves clean-performance retention by adjusting original-versus-augmentation weighting using feature disagreement signals. We evaluate on PACS, VLCS, and OfficeHome under PGD attacks at various attack rates. Across benchmarks, SAFER improves resilience of TTA methods to adversarial attacks while maintaining competitive clean performance.

测试时适应对抗鲁棒性模型融合无监督学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。