Towards Class-wise Fair Adversarial Training via Anti-Bias Soft Label Distillation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhao, Shiji, Chen, Chi, Duan, Ranjie, Wang, Xizhe, Wei, Xingxing
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915335328759808
author Zhao, Shiji
Chen, Chi
Duan, Ranjie
Wang, Xizhe
Wei, Xingxing
author_facet Zhao, Shiji
Chen, Chi
Duan, Ranjie
Wang, Xizhe
Wei, Xingxing
contents Adversarial Training (AT) is widely recognized as an effective approach to enhance the adversarial robustness of Deep Neural Networks. As a variant of AT, Adversarial Robustness Distillation (ARD) has shown outstanding performance in enhancing the robustness of small models. However, both AT and ARD face robust fairness issue: these models tend to display strong adversarial robustness against some classes (easy classes) while demonstrating weak adversarial robustness against others (hard classes). This paper explores the underlying factors of this problem and points out the smoothness degree of soft labels for different classes significantly impacts the robust fairness from both empirical observation and theoretical analysis. Based on the above exploration, we propose Anti-Bias Soft Label Distillation (ABSLD) within the Knowledge Distillation framework to enhance the adversarial robust fairness. Specifically, ABSLD adaptively reduces the student's error risk gap between different classes, which is accomplished by adjusting the class-wise smoothness degree of teacher's soft labels during the training process, and the adjustment is managed by assigning varying temperatures to different classes. Additionally, as a label-based approach, ABSLD is highly adaptable and can be integrated with the sample-based methods. Extensive experiments demonstrate ABSLD outperforms state-of-the-art methods on the comprehensive performance of robustness and fairness.
format Preprint
id arxiv_https___arxiv_org_abs_2506_08611
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Towards Class-wise Fair Adversarial Training via Anti-Bias Soft Label Distillation
Zhao, Shiji
Chen, Chi
Duan, Ranjie
Wang, Xizhe
Wei, Xingxing
Computer Vision and Pattern Recognition
Adversarial Training (AT) is widely recognized as an effective approach to enhance the adversarial robustness of Deep Neural Networks. As a variant of AT, Adversarial Robustness Distillation (ARD) has shown outstanding performance in enhancing the robustness of small models. However, both AT and ARD face robust fairness issue: these models tend to display strong adversarial robustness against some classes (easy classes) while demonstrating weak adversarial robustness against others (hard classes). This paper explores the underlying factors of this problem and points out the smoothness degree of soft labels for different classes significantly impacts the robust fairness from both empirical observation and theoretical analysis. Based on the above exploration, we propose Anti-Bias Soft Label Distillation (ABSLD) within the Knowledge Distillation framework to enhance the adversarial robust fairness. Specifically, ABSLD adaptively reduces the student's error risk gap between different classes, which is accomplished by adjusting the class-wise smoothness degree of teacher's soft labels during the training process, and the adjustment is managed by assigning varying temperatures to different classes. Additionally, as a label-based approach, ABSLD is highly adaptable and can be integrated with the sample-based methods. Extensive experiments demonstrate ABSLD outperforms state-of-the-art methods on the comprehensive performance of robustness and fairness.
title Towards Class-wise Fair Adversarial Training via Anti-Bias Soft Label Distillation
topic Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2506.08611