Fine-tuning only the few transformer layers with the highest sharpness, using SAM while freezing the rest, improves clean and adversarial accuracy over full-model adversarial training baselines.
Minimally distorted adversarial examples with a fast adaptive boundary attack
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
citation-role summary
background 1
citation-polarity summary
fields
cs.CV 1years
2025 1verdicts
CONDITIONAL 1roles
background 1polarities
unclear 1representative citing papers
citing papers explorer
-
SAFER: Sharpness Aware layer-selective Finetuning for Enhanced Robustness in vision transformers
Fine-tuning only the few transformer layers with the highest sharpness, using SAM while freezing the rest, improves clean and adversarial accuracy over full-model adversarial training baselines.