Partially Recentralization Softmax Loss for Vision-Language Models Robustness

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Hao, Jiang, Jinzhe, Zhang, Xin, Li, Chen
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912963792732160
author Wang, Hao
Jiang, Jinzhe
Zhang, Xin
Li, Chen
author_facet Wang, Hao
Jiang, Jinzhe
Zhang, Xin
Li, Chen
contents As Large Language Models make a breakthrough in natural language processing tasks (NLP), multimodal technique becomes extremely popular. However, it has been shown that multimodal NLP are vulnerable to adversarial attacks, where the outputs of a model can be dramatically changed by a perturbation to the input. While several defense techniques have been proposed both in computer vision and NLP models, the multimodal robustness of models have not been fully explored. In this paper, we study the adversarial robustness provided by modifying loss function of pre-trained multimodal models, by restricting top K softmax outputs. Based on the evaluation and scoring, our experiments show that after a fine-tuning, adversarial robustness of pre-trained models can be significantly improved, against popular attacks. Further research should be studying, such as output diversity, generalization and the robustness-performance trade-off of this kind of loss functions. Our code will be available after this paper is accepted
format Preprint
id arxiv_https___arxiv_org_abs_2402_03627
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Partially Recentralization Softmax Loss for Vision-Language Models Robustness
Wang, Hao
Jiang, Jinzhe
Zhang, Xin
Li, Chen
Computation and Language
Artificial Intelligence
I.2.7
As Large Language Models make a breakthrough in natural language processing tasks (NLP), multimodal technique becomes extremely popular. However, it has been shown that multimodal NLP are vulnerable to adversarial attacks, where the outputs of a model can be dramatically changed by a perturbation to the input. While several defense techniques have been proposed both in computer vision and NLP models, the multimodal robustness of models have not been fully explored. In this paper, we study the adversarial robustness provided by modifying loss function of pre-trained multimodal models, by restricting top K softmax outputs. Based on the evaluation and scoring, our experiments show that after a fine-tuning, adversarial robustness of pre-trained models can be significantly improved, against popular attacks. Further research should be studying, such as output diversity, generalization and the robustness-performance trade-off of this kind of loss functions. Our code will be available after this paper is accepted
title Partially Recentralization Softmax Loss for Vision-Language Models Robustness
topic Computation and Language
Artificial Intelligence
I.2.7
url https://arxiv.org/abs/2402.03627