Finetune Like You Pretrain: Boosting Zero-shot Adversarial Robustness in Vision-language Models
AI 摘要
AdvFLYP通过模拟CLIP预训练方式进行对抗微调,提升视觉-语言模型的零样本对抗鲁棒性。
主要贡献
- 提出AdvFLYP对抗微调范式,模仿CLIP预训练过程
- 使用图像-文本对创建对抗样本,并采用对比损失
- 提出特征和logit层面的正则化方法
方法论
使用网络收集的图像-文本对进行对抗微调,采用对比损失并引入特征和logit层面的正则化。
原文摘要
Despite their impressive zero-shot abilities, vision-language models such as CLIP have been shown to be susceptible to adversarial attacks. To enhance its adversarial robustness, recent studies finetune the pretrained vision encoder of CLIP with adversarial examples on a proxy dataset such as ImageNet by aligning adversarial images with correct class labels. However, these methods overlook the important roles of training data distributions and learning objectives, resulting in reduced zero-shot capabilities and limited transferability of robustness across domains and datasets. In this work, we propose a simple yet effective paradigm AdvFLYP, which follows the training recipe of CLIP's pretraining process when performing adversarial finetuning to the model. Specifically, AdvFLYP finetunes CLIP with adversarial images created based on image-text pairs collected from the web, and match them with their corresponding texts via a contrastive loss. To alleviate distortion of adversarial image embeddings of noisy web images, we further propose to regularise AdvFLYP by penalising deviation of adversarial image features. We show that logit- and feature-level regularisation terms benefit robustness and clean accuracy, respectively. Extensive experiments on 14 downstream datasets spanning various domains show the superiority of our paradigm over mainstream practices. Our code and model weights are released at https://github.com/Sxing2/AdvFLYP.