Robust Dataset Distillation by Matching Adversarial Trajectories

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Lai, Wei, Ding, Tianyu, dongdong, ren, Wang, Lei, Huo, Jing, Gao, Yang, Li, Wenbin
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912276917780480
author Lai, Wei
Ding, Tianyu
dongdong, ren
Wang, Lei
Huo, Jing
Gao, Yang
Li, Wenbin
author_facet Lai, Wei
Ding, Tianyu
dongdong, ren
Wang, Lei
Huo, Jing
Gao, Yang
Li, Wenbin
contents Dataset distillation synthesizes compact datasets that enable models to achieve performance comparable to training on the original large-scale datasets. However, existing distillation methods overlook the robustness of the model, resulting in models that are vulnerable to adversarial attacks when trained on distilled data. To address this limitation, we introduce the task of ``robust dataset distillation", a novel paradigm that embeds adversarial robustness into the synthetic datasets during the distillation process. We propose Matching Adversarial Trajectories (MAT), a method that integrates adversarial training into trajectory-based dataset distillation. MAT incorporates adversarial samples during trajectory generation to obtain robust training trajectories, which are then used to guide the distillation process. As experimentally demonstrated, even through natural training on our distilled dataset, models can achieve enhanced adversarial robustness while maintaining competitive accuracy compared to existing distillation methods. Our work highlights robust dataset distillation as a new and important research direction and provides a strong baseline for future research to bridge the gap between efficient training and adversarial robustness.
format Preprint
id arxiv_https___arxiv_org_abs_2503_12069
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Robust Dataset Distillation by Matching Adversarial Trajectories
Lai, Wei
Ding, Tianyu
dongdong, ren
Wang, Lei
Huo, Jing
Gao, Yang
Li, Wenbin
Computer Vision and Pattern Recognition
Dataset distillation synthesizes compact datasets that enable models to achieve performance comparable to training on the original large-scale datasets. However, existing distillation methods overlook the robustness of the model, resulting in models that are vulnerable to adversarial attacks when trained on distilled data. To address this limitation, we introduce the task of ``robust dataset distillation", a novel paradigm that embeds adversarial robustness into the synthetic datasets during the distillation process. We propose Matching Adversarial Trajectories (MAT), a method that integrates adversarial training into trajectory-based dataset distillation. MAT incorporates adversarial samples during trajectory generation to obtain robust training trajectories, which are then used to guide the distillation process. As experimentally demonstrated, even through natural training on our distilled dataset, models can achieve enhanced adversarial robustness while maintaining competitive accuracy compared to existing distillation methods. Our work highlights robust dataset distillation as a new and important research direction and provides a strong baseline for future research to bridge the gap between efficient training and adversarial robustness.
title Robust Dataset Distillation by Matching Adversarial Trajectories
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2503.12069