Robustness Meets Uncertainty: Evidential Adversarial Training for Robust Selective Classification
arXiv:2607. 03075v1 Announce Type: new Abstract: Safety-critical applications require classifiers that are both robust and reliable.
The paper introduces Conflict‑Aware Evidential Deep Learning (C‑EDL), a lightweight post‑hoc method that improves uncertainty quantification for deep learning models. C‑EDL applies diverse, task‑preserving transformations to each input and uses representational disagreement to adjust predictions, thereby reducing overconfident errors on adversarial and out‑of‑distribution data. Experiments demonstrate that C‑EDL outperforms existing Evidential Deep Learning variants and baselines, achieving up to 55 % reduction in coverage for OOD data and 90 % for adversarial data across multiple datasets and attack types.
arXiv:2607. 03075v1 Announce Type: new Abstract: Safety-critical applications require classifiers that are both robust and reliable.
The paper introduces CLEAR, a lightweight, task‑agnostic post‑hoc method that enhances evidential robustness in deep learning models without retraining. CLEAR uses held‑out calibration data to map the geometry of the model’s latent space, then generates perturbation views at inference to detect latent conflict. When high conflict is found, CLEAR selectively reduces evidential strength while preserving evidence for latent‑consistent inputs, achieving significant improvements in OOD and adversarial AUROC on ImageNet→CUB and running much faster than competing methods.
arXiv:2606. 28416v1 Announce Type: cross Abstract: Deep neural networks (DNNs) have shown outstanding performance in visual recognition tasks within vision sensor networks; however, they are still vulnerable to adversarial manipulations and imperceptible perturbations that can lead to erroneous predictions.
arXiv:2606. 01746v1 Announce Type: cross Abstract: Modern neural networks are highly susceptible to adversarial perturbations.
arXiv:2606. 01437v1 Announce Type: cross Abstract: Deep Neural Networks (DNNs) are highly susceptible to adversarial perturbations, leading to extensive research on robustness for safety-critical applications.
arXiv:2606. 31653v1 Announce Type: cross Abstract: Certified training aims to produce models whose predictions can be formally verified against adversarial perturbations, typically by optimising upper bounds on the worst-case loss over an allowed perturbation set.
arXiv:2512. 12997v2 Announce Type: replace-cross Abstract: CLIP delivers strong zero-shot classification but remains highly vulnerable to adversarial attacks.
arXiv:2511. 13749v2 Announce Type: replace Abstract: Deep neural networks are known to be vulnerable to adversarial perturbations, which are small, carefully crafted inputs that lead to incorrect predictions.
arXiv:2610.03142v1 Announce Type: new Abstract: Deep neural networks remain vulnerable to adversarial perturbations, which can distort not only predictions but also confidence scores, undermining unc...
arXiv:2510. 09288v2 Announce Type: replace-cross Abstract: The vulnerability of machine learning models to adversarial attacks remains a critical societal security challenge.
arXiv:2606. 08467v1 Announce Type: cross Abstract: While confidence calibration is essential for trustworthy decision-making in safety-critical applications, the robustness of calibrated GNNs to adversarial structural perturbations remains largely unexplored.
The paper introduces Adversarial Importance Sampling (Advis), a technique that leverages importance sampling over standard training trajectories to estimate and optimize worst‑case returns without extra environment interactions or auxiliary networks, thereby capturing long‑term robustness. It also presents advrl, a modular PyTorch library that consolidates existing robustness methods and adversarial attacks into single‑file implementations for easier prototyping and reproducible evaluation. Finally, the authors highlight that optimal adversarial hyperparameters do not transfer across agents, prompting evaluation against a broader set of attackers (6–14× more configurations) and demonstrate the effectiveness of their approach on continuous control tasks.