Pith. sign in

REVIEW 2 cited by

Adversarial Feature Alignment: Balancing Robustness and Accuracy in Deep Learning via Adversarial Training

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2402.12187 v1 pith:KK5TV5Q4 submitted 2024-02-19 cs.CV cs.CRcs.LG

classification cs.CVcs.CRcs.LG
keywords adversarialaccuracylearningfeaturerobustnessdeeptrainingalignment
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Deep learning models continue to advance in accuracy, yet they remain vulnerable to adversarial attacks, which often lead to the misclassification of adversarial examples. Adversarial training is used to mitigate this problem by increasing robustness against these attacks. However, this approach typically reduces a model's standard accuracy on clean, non-adversarial samples. The necessity for deep learning models to balance both robustness and accuracy for security is obvious, but achieving this balance remains challenging, and the underlying reasons are yet to be clarified. This paper proposes a novel adversarial training method called Adversarial Feature Alignment (AFA), to address these problems. Our research unveils an intriguing insight: misalignment within the feature space often leads to misclassification, regardless of whether the samples are benign or adversarial. AFA mitigates this risk by employing a novel optimization algorithm based on contrastive learning to alleviate potential feature misalignment. Through our evaluations, we demonstrate the superior performance of AFA. The baseline AFA delivers higher robust accuracy than previous adversarial contrastive learning methods while minimizing the drop in clean accuracy to 1.86% and 8.91% on CIFAR10 and CIFAR100, respectively, in comparison to cross-entropy. We also show that joint optimization of AFA and TRADES, accompanied by data augmentation using a recent diffusion model, achieves state-of-the-art accuracy and robustness.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. ST-DAI: Single-shot 2.5D Spatial Transcriptomics with Intra-Sample Domain Adaptive Imputation for Cost-efficient 3D Reconstruction

    eess.IV 2025-07 conditional novelty 6.0 of 10

    A domain-adaptive pipeline imputes full gene expression on sparsely sampled tissue sections using a fully-sampled central section, reducing 3D spatial transcriptomics cost to about 25% of full sampling.

  2. SynthGenNet: a self-supervised approach for test-time generalization using synthetic multi-source domain mixing of street view images

    cs.CV 2025-09 reject novelty 3.0 of 10

    SynthGenNet reports 49.79 mIoU on IDD and 48.33 on Cityscapes by mixing multiple synthetic sources with diverse self-supervised losses, but the method actually uses unlabeled target images during training, so it is no...

Pith tools