arXiv AI

A Step Towards Robust Unsupervised Domain Adaptation via Fine-Tuning and Reinforcement Learning

arXiv:2607. 03600v1 Announce Type: cross Abstract: Adversarial robustness in Unsupervised Domain Adaptation (UDA) remains a significant challenge due to noisy pseudo labels and inherent distributional shifts between the clean source and adversarially perturbed target domains.

arXiv Computer Vision
Sep 7

FSPGD: Rethinking Black-box Attacks on Semantic Segmentation

FSPGD introduces a feature-space black-box attack for semantic segmentation that targets intermediate representations rather than just output logits. The method uses a dual loss: an external loss to disrupt cross-model feature alignment and an internal loss to reduce consistency among same-class instances. Experiments on Pascal VOC 2012 and Cityscapes show that FSPGD outperforms existing logit-level and segmentation-specific attacks across CNN and Transformer backbones, and its adversarial examples improve robustness when used for training.

By Eun-Sol Park, MiSo Park, Yong-Goo Shin
arXiv Computer Vision
Sep 7

PAPT++: Risk-Aware Adversarial Tuning and Generation for Single Domain Generalization

PAPT++ is a risk‑aware adversarial generation‑training framework designed to improve single domain generalization. It learns diverse semantic reference images per class and uses them as denoising targets in classifier‑guided diffusion synthesis, thereby generating challenging yet semantically consistent samples. These samples are iteratively combined with source data to update the classifier, progressively exposing it to difficult variations and enhancing generalization performance on standard benchmarks.

By Zhipeng Xu, De Cheng, Xinyang Jiang, Lingfeng He, Huaijie Wang, Dongsheng Li, Nannan Wang, Xinbo Gao
arXiv AI
Aug 19

Learning What Not to Learn: Adversarial Disentangled Prompt Tuning for Robust Vision-Language Models

The paper introduces ADAPT, an adversarial disentangled prompt tuning framework designed to improve the robustness of vision‑language models. ADAPT employs a dual‑prompt strategy: a target prompt learns robust features while a set of decoy prompts capture pseudo‑robust, non‑generalizable shortcuts. By enforcing orthogonality between target and decoy prompts, the method mitigates robust generalization overfitting and provides a theoretical error bound for unseen classes, leading to significant empirical robustness gains.

By Yang Chen, Zhan Zhuang, Yanbin Wei, Zebin Chen, Hua Liu, Yu Zhang