Killing it with Zero-Shot: Adversarially Robust Novelty Detection

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Mirzaei, Hossein, Jafari, Mohammad, Dehbashi, Hamid Reza, Taghavi, Zeinab Sadat, Sabokrou, Mohammad, Rohban, Mohammad Hossein
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866909466440499200
author Mirzaei, Hossein
Jafari, Mohammad
Dehbashi, Hamid Reza
Taghavi, Zeinab Sadat
Sabokrou, Mohammad
Rohban, Mohammad Hossein
author_facet Mirzaei, Hossein
Jafari, Mohammad
Dehbashi, Hamid Reza
Taghavi, Zeinab Sadat
Sabokrou, Mohammad
Rohban, Mohammad Hossein
contents Novelty Detection (ND) plays a crucial role in machine learning by identifying new or unseen data during model inference. This capability is especially important for the safe and reliable operation of automated systems. Despite advances in this field, existing techniques often fail to maintain their performance when subject to adversarial attacks. Our research addresses this gap by marrying the merits of nearest-neighbor algorithms with robust features obtained from models pretrained on ImageNet. We focus on enhancing the robustness and performance of ND algorithms. Experimental results demonstrate that our approach significantly outperforms current state-of-the-art methods across various benchmarks, particularly under adversarial conditions. By incorporating robust pretrained features into the k-NN algorithm, we establish a new standard for performance and robustness in the field of robust ND. This work opens up new avenues for research aimed at fortifying machine learning systems against adversarial vulnerabilities. Our implementation is publicly available at https://github.com/rohban-lab/ZARND.
format Preprint
id arxiv_https___arxiv_org_abs_2501_15271
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Killing it with Zero-Shot: Adversarially Robust Novelty Detection
Mirzaei, Hossein
Jafari, Mohammad
Dehbashi, Hamid Reza
Taghavi, Zeinab Sadat
Sabokrou, Mohammad
Rohban, Mohammad Hossein
Machine Learning
Novelty Detection (ND) plays a crucial role in machine learning by identifying new or unseen data during model inference. This capability is especially important for the safe and reliable operation of automated systems. Despite advances in this field, existing techniques often fail to maintain their performance when subject to adversarial attacks. Our research addresses this gap by marrying the merits of nearest-neighbor algorithms with robust features obtained from models pretrained on ImageNet. We focus on enhancing the robustness and performance of ND algorithms. Experimental results demonstrate that our approach significantly outperforms current state-of-the-art methods across various benchmarks, particularly under adversarial conditions. By incorporating robust pretrained features into the k-NN algorithm, we establish a new standard for performance and robustness in the field of robust ND. This work opens up new avenues for research aimed at fortifying machine learning systems against adversarial vulnerabilities. Our implementation is publicly available at https://github.com/rohban-lab/ZARND.
title Killing it with Zero-Shot: Adversarially Robust Novelty Detection
topic Machine Learning
url https://arxiv.org/abs/2501.15271