MedBN: Robust Test-Time Adaptation against Malicious Test Samples

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Park, Hyejin, Hwang, Jeongyeon, Mun, Sunung, Park, Sangdon, Ok, Jungseul
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909154193440768
author Park, Hyejin
Hwang, Jeongyeon
Mun, Sunung
Park, Sangdon
Ok, Jungseul
author_facet Park, Hyejin
Hwang, Jeongyeon
Mun, Sunung
Park, Sangdon
Ok, Jungseul
contents Test-time adaptation (TTA) has emerged as a promising solution to address performance decay due to unforeseen distribution shifts between training and test data. While recent TTA methods excel in adapting to test data variations, such adaptability exposes a model to vulnerability against malicious examples, an aspect that has received limited attention. Previous studies have uncovered security vulnerabilities within TTA even when a small proportion of the test batch is maliciously manipulated. In response to the emerging threat, we propose median batch normalization (MedBN), leveraging the robustness of the median for statistics estimation within the batch normalization layer during test-time inference. Our method is algorithm-agnostic, thus allowing seamless integration with existing TTA frameworks. Our experimental results on benchmark datasets, including CIFAR10-C, CIFAR100-C and ImageNet-C, consistently demonstrate that MedBN outperforms existing approaches in maintaining robust performance across different attack scenarios, encompassing both instant and cumulative attacks. Through extensive experiments, we show that our approach sustains the performance even in the absence of attacks, achieving a practical balance between robustness and performance.
format Preprint
id arxiv_https___arxiv_org_abs_2403_19326
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle MedBN: Robust Test-Time Adaptation against Malicious Test Samples
Park, Hyejin
Hwang, Jeongyeon
Mun, Sunung
Park, Sangdon
Ok, Jungseul
Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
Test-time adaptation (TTA) has emerged as a promising solution to address performance decay due to unforeseen distribution shifts between training and test data. While recent TTA methods excel in adapting to test data variations, such adaptability exposes a model to vulnerability against malicious examples, an aspect that has received limited attention. Previous studies have uncovered security vulnerabilities within TTA even when a small proportion of the test batch is maliciously manipulated. In response to the emerging threat, we propose median batch normalization (MedBN), leveraging the robustness of the median for statistics estimation within the batch normalization layer during test-time inference. Our method is algorithm-agnostic, thus allowing seamless integration with existing TTA frameworks. Our experimental results on benchmark datasets, including CIFAR10-C, CIFAR100-C and ImageNet-C, consistently demonstrate that MedBN outperforms existing approaches in maintaining robust performance across different attack scenarios, encompassing both instant and cumulative attacks. Through extensive experiments, we show that our approach sustains the performance even in the absence of attacks, achieving a practical balance between robustness and performance.
title MedBN: Robust Test-Time Adaptation against Malicious Test Samples
topic Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2403.19326