arXiv:2607.18195cs.CVcs.LG2026-07

为卷积扰动设计可证明鲁棒的训练方法,提升视觉模型安全性。

Certified Training for Convolutional Perturbations

  • 利用高效编码卷积扰动,实现可证明鲁棒性训练。
  • 在CIFAR10上对合理强度运动模糊,鲁棒准确率超80%。
  • 适合对安全性要求高的视觉系统部署场景。

视觉模型在运行时因相机抖动引发的运动模糊等扰动下表现脆弱,影响其在关键应用中的部署,例如物体检测器可能漏检目标。尽管数据增强或对抗训练可提升经验鲁棒性,但缺乏形式化安全保证,难以发现并缓解隐藏漏洞。本文提出一种新型认证训练方法,通过高效编码卷积扰动,训练出可证明鲁棒的模型。该方法显著优于对抗训练,在CIFAR10上对合理强度的运动模糊,实现超过80%的鲁棒准确率,同时保持与原有模型相当的标准准确率。

原文摘要 · Abstract (English)

Vision models have been found to be susceptible to perturbations such as motion blur induced at runtime by a shaking camera. This impedes their deployment in critical applications since phenomena such as slightly blurred vision might lead to failures, for example an object detector missing objects. While methods such as data augmentation or Adversarial Training can improve empirical robustness, they lack formal safety guarantees, making it difficult to identify and mitigate hidden vulnerabilities. We introduce a novel Certified Training approach that leverages an efficient encoding of convolutional perturbations to train provably robust models. Our method significantly outperforms Adversarial Training, achieving, for example, over 80% robust accuracy against motion blur of reasonable intensity on CIFAR10 while maintaining comparable standard accuracy.

模型鲁棒性认证训练卷积扰动视觉安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。