DD-RobustBench: An Adversarial Robustness Benchmark for Dataset Distillation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wu, Yifan, Du, Jiawei, Liu, Ping, Lin, Yuewei, Xu, Wei, Cheng, Wenqing
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909347162882048
author Wu, Yifan
Du, Jiawei
Liu, Ping
Lin, Yuewei
Xu, Wei
Cheng, Wenqing
author_facet Wu, Yifan
Du, Jiawei
Liu, Ping
Lin, Yuewei
Xu, Wei
Cheng, Wenqing
contents Dataset distillation is an advanced technique aimed at compressing datasets into significantly smaller counterparts, while preserving formidable training performance. Significant efforts have been devoted to promote evaluation accuracy under limited compression ratio while overlooked the robustness of distilled dataset. In this work, we introduce a comprehensive benchmark that, to the best of our knowledge, is the most extensive to date for evaluating the adversarial robustness of distilled datasets in a unified way. Our benchmark significantly expands upon prior efforts by incorporating a wider range of dataset distillation methods, including the latest advancements such as TESLA and SRe2L, a diverse array of adversarial attack methods, and evaluations across a broader and more extensive collection of datasets such as ImageNet-1K. Moreover, we assessed the robustness of these distilled datasets against representative adversarial attack algorithms like PGD and AutoAttack, while exploring their resilience from a frequency perspective. We also discovered that incorporating distilled data into the training batches of the original dataset can yield to improvement of robustness.
format Preprint
id arxiv_https___arxiv_org_abs_2403_13322
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle DD-RobustBench: An Adversarial Robustness Benchmark for Dataset Distillation
Wu, Yifan
Du, Jiawei
Liu, Ping
Lin, Yuewei
Xu, Wei
Cheng, Wenqing
Computer Vision and Pattern Recognition
Dataset distillation is an advanced technique aimed at compressing datasets into significantly smaller counterparts, while preserving formidable training performance. Significant efforts have been devoted to promote evaluation accuracy under limited compression ratio while overlooked the robustness of distilled dataset. In this work, we introduce a comprehensive benchmark that, to the best of our knowledge, is the most extensive to date for evaluating the adversarial robustness of distilled datasets in a unified way. Our benchmark significantly expands upon prior efforts by incorporating a wider range of dataset distillation methods, including the latest advancements such as TESLA and SRe2L, a diverse array of adversarial attack methods, and evaluations across a broader and more extensive collection of datasets such as ImageNet-1K. Moreover, we assessed the robustness of these distilled datasets against representative adversarial attack algorithms like PGD and AutoAttack, while exploring their resilience from a frequency perspective. We also discovered that incorporating distilled data into the training batches of the original dataset can yield to improvement of robustness.
title DD-RobustBench: An Adversarial Robustness Benchmark for Dataset Distillation
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2403.13322