arrow
Return

Robust Few-Shot Learning Without Using Any Adversarial Samples

delete2025-02-01
delete0
delete
OA
AI
G
Gaurav Kumar Nayak
R
Ruchit Rawal
I
Inder Khatri
A
Anirban Chakraborty *
DOI:10.1109/TNNLS.2023.3336996delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The high cost of acquiring and annotating samples has made the few-shot learning problem of prime importance. Existing works mainly focus on improving performance on clean data and overlook robustness concerns on the data perturbed with adversarial noise. Recently, a few efforts have been made to combine the few-shot problem with the robustness objective using sophisticated meta-learning techniques. These methods rely on the generation of adversarial samples in every episode of training, which further adds to the computational burden. To avoid such time-consuming and complicated procedures, we propose a simple but effective alternative that does not require any adversarial samples. Inspired by the cognitive decision-making process in humans, we enforce high-level feature matching between the base class data and their corresponding low-frequency samples in the pretraining stage via self distillation. The model is then fine-tuned on the samples of novel classes where we additionally improve the discriminability of low-frequency query set features via cosine similarity. On a one-shot setting of the CIFAR-FS dataset, our method yields a massive improvement of 60.55% and 62.05% in adversarial accuracy on the projected gradient descent (PGD) and state-of-the-art auto attack, respectively, with a minor drop in clean accuracy compared to the baseline. Moreover, our method only takes 1.69x of the standard training time while being approximate to 5x faster than the state-of-the-art adversarial meta-learning methods. The code is available at https://github.com/vcl-iisc/robust-few-shot-learning.
Keywords:
Robustness
Training
Metalearning
Computational modeling
Optimization
Task analysis
Standards
Adversarial defense
adversarial robustness
few-shot learning
Fourier transform
self distillation

Journal

IEEE Transactions on Neural Networks and Learning Systems cover
IEEE Transactions on Neural Networks and Learning Systems
IF:
8.9
Papers:
7.5K
Citations:
7.2W

Organization

State University System of Florida cover
State University System of Florida
Scholars:
12.7W
Papers: 10.9W
Citations: 130
N
New York University
Scholars:
4.4W
Papers: 3.9W
Citations: 5.8W
U
University of Central Florida
Scholars:
8.6K
Papers: 6.8K
Citations: 1.4W
M
Max Planck Society
Scholars:
8.2W
Papers: 7.7W
Citations: 3.3W
researcher View more organizations