Evolution-based Region Adversarial Prompt Learning for Robustness Enhancement in Vision-Language Models

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jia, Xiaojun, Gao, Sensen, Qin, Simeng, Ma, Ke, Li, Xinfeng, Huang, Yihao, Dong, Wei, Liu, Yang, Cao, Xiaochun
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910879963938816
author Jia, Xiaojun
Gao, Sensen
Qin, Simeng
Ma, Ke
Li, Xinfeng
Huang, Yihao
Dong, Wei
Liu, Yang
Cao, Xiaochun
author_facet Jia, Xiaojun
Gao, Sensen
Qin, Simeng
Ma, Ke
Li, Xinfeng
Huang, Yihao
Dong, Wei
Liu, Yang
Cao, Xiaochun
contents Large pre-trained vision-language models (VLMs), such as CLIP, demonstrate impressive generalization but remain highly vulnerable to adversarial examples (AEs). Previous work has explored robust text prompts through adversarial training, achieving some improvement in both robustness and generalization. However, they primarily rely on singlegradient direction perturbations (e.g., PGD) to generate AEs, which lack diversity, resulting in limited improvement in adversarial robustness. To address these limitations, we propose an evolution-based region adversarial prompt tuning method called ER-APT, which combines gradient methods with genetic evolution to generate more diverse and challenging AEs. In each training iteration, we first generate AEs using traditional gradient-based methods. Subsequently, a genetic evolution mechanism incorporating selection, mutation, and crossover is applied to optimize the AEs, ensuring a broader and more aggressive perturbation distribution.The final evolved AEs are used for prompt tuning, achieving region-based adversarial optimization instead of conventional single-point adversarial prompt tuning. We also propose a dynamic loss weighting method to adjust prompt learning efficiency for accuracy and robustness. Experimental evaluations on various benchmark datasets demonstrate the superiority of our proposed method, outperforming stateof-the-art APT methods. The code is released at https://github.com/jiaxiaojunQAQ/ER-APT.
format Preprint
id arxiv_https___arxiv_org_abs_2503_12874
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Evolution-based Region Adversarial Prompt Learning for Robustness Enhancement in Vision-Language Models
Jia, Xiaojun
Gao, Sensen
Qin, Simeng
Ma, Ke
Li, Xinfeng
Huang, Yihao
Dong, Wei
Liu, Yang
Cao, Xiaochun
Computer Vision and Pattern Recognition
Large pre-trained vision-language models (VLMs), such as CLIP, demonstrate impressive generalization but remain highly vulnerable to adversarial examples (AEs). Previous work has explored robust text prompts through adversarial training, achieving some improvement in both robustness and generalization. However, they primarily rely on singlegradient direction perturbations (e.g., PGD) to generate AEs, which lack diversity, resulting in limited improvement in adversarial robustness. To address these limitations, we propose an evolution-based region adversarial prompt tuning method called ER-APT, which combines gradient methods with genetic evolution to generate more diverse and challenging AEs. In each training iteration, we first generate AEs using traditional gradient-based methods. Subsequently, a genetic evolution mechanism incorporating selection, mutation, and crossover is applied to optimize the AEs, ensuring a broader and more aggressive perturbation distribution.The final evolved AEs are used for prompt tuning, achieving region-based adversarial optimization instead of conventional single-point adversarial prompt tuning. We also propose a dynamic loss weighting method to adjust prompt learning efficiency for accuracy and robustness. Experimental evaluations on various benchmark datasets demonstrate the superiority of our proposed method, outperforming stateof-the-art APT methods. The code is released at https://github.com/jiaxiaojunQAQ/ER-APT.
title Evolution-based Region Adversarial Prompt Learning for Robustness Enhancement in Vision-Language Models
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2503.12874