arrow
Return

Decoupling representation learning and classifier for long-tailed adversarial training

delete2025-10-24
delete0
PRE
AI
H
Hengheng Xiong
D
Dapeng Man
J
Jiguang Lv
徐晨 (Xu Chen)
F
Fanyi Zeng
Y
Yuyan Shi
M
Mingzhu Lai
W
Wu Yang
DOI:10.1016/j.patcog.2025.112607delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Adversarial training effectively enhances model robustness against adversarial attacks, yet its effectiveness is primarily demonstrated on balanced datasets. As real-world scenarios typically exhibit long-tailed distributions, advancing adversarial training toward such practical scenarios is crucial. Previous studies on long-tailed distributions robustness have primarily focused on integrating adversarial training with rebalancing strategies under a joint learning framework for feature representations and classifiers. However, this joint learning framework makes it unclear how adversarial robustness is achieved by rebalancing strategies, whether through learning robust representations or by shifting classifier decision boundaries. In this paper, we decouple the learning process into representation learning and classifier to investigate the effect of rebalancing strategies on both stages. Through systematic analysis, we uncover two key insights: rebalancing strategies may not be essential for robust representation learning, and class imbalance can be effectively mitigated by recalibrating the decision boundaries of the classifier alone. Motivated by these insights, we propose a Two-stage Decoupled Learning Framework (TDLF): a representation learning stage that focuses exclusively on robust feature representations, leveraging adversarial contrastive learning to obtain perturbation-invariant representations, and a classifier learning stage incorporating rebalancing strategies solely to address the class imbalance issue. Extensive experiments conducted on three long-tailed datasets demonstrate the effectiveness of our method. Compared to the state-of-the-art method AT-BSL-RA, our method achieves a 9.38 % performance improvement against projected gradient descent (PGD) attack on CIFAR-10-LT.

Journal

Pattern Recognition cover
Pattern Recognition
IF:
7.6
Papers:
1.3W
Citations:
4.5W

Organization

C
College of Computer Science and Technology
Scholars:
854
Papers: 298
Citations: 0
S
School of Mathematics and Statistics
Scholars:
906
Papers: 486
Citations: 0