Generalist++: A Meta-learning Framework for Mitigating Trade-off in Adversarial Training

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Yisen, Mo, Yichuan, Wang, Hongjun, Li, Junyi, Lin, Zhouchen
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915555765649408
author Wang, Yisen
Mo, Yichuan
Wang, Hongjun
Li, Junyi
Lin, Zhouchen
author_facet Wang, Yisen
Mo, Yichuan
Wang, Hongjun
Li, Junyi
Lin, Zhouchen
contents Despite the rapid progress of neural networks, they remain highly vulnerable to adversarial examples, for which adversarial training (AT) is currently the most effective defense. While AT has been extensively studied, its practical applications expose two major limitations: natural accuracy tends to degrade significantly compared with standard training, and robustness does not transfer well across attacks crafted under different norm constraints. Unlike prior works that attempt to address only one issue within a single network, we propose to partition the overall generalization goal into multiple sub-tasks, each assigned to a dedicated base learner. By specializing in its designated objective, each base learner quickly becomes an expert in its field. In the later stages of training, we interpolate their parameters to form a knowledgeable global learner, while periodically redistributing the global parameters back to the base learners to prevent their optimization trajectories from drifting too far from the shared target. We term this framework Generalist and introduce three variants tailored to different application scenarios. Both theoretical analysis and extensive experiments demonstrate that Generalist achieves lower generalization error and significantly alleviates the trade-off problems compared with baseline methods. Our results suggest that Generalist provides a promising step toward developing fully robust classifiers in the future.
format Preprint
id arxiv_https___arxiv_org_abs_2510_13361
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Generalist++: A Meta-learning Framework for Mitigating Trade-off in Adversarial Training
Wang, Yisen
Mo, Yichuan
Wang, Hongjun
Li, Junyi
Lin, Zhouchen
Machine Learning
Artificial Intelligence
Cryptography and Security
Despite the rapid progress of neural networks, they remain highly vulnerable to adversarial examples, for which adversarial training (AT) is currently the most effective defense. While AT has been extensively studied, its practical applications expose two major limitations: natural accuracy tends to degrade significantly compared with standard training, and robustness does not transfer well across attacks crafted under different norm constraints. Unlike prior works that attempt to address only one issue within a single network, we propose to partition the overall generalization goal into multiple sub-tasks, each assigned to a dedicated base learner. By specializing in its designated objective, each base learner quickly becomes an expert in its field. In the later stages of training, we interpolate their parameters to form a knowledgeable global learner, while periodically redistributing the global parameters back to the base learners to prevent their optimization trajectories from drifting too far from the shared target. We term this framework Generalist and introduce three variants tailored to different application scenarios. Both theoretical analysis and extensive experiments demonstrate that Generalist achieves lower generalization error and significantly alleviates the trade-off problems compared with baseline methods. Our results suggest that Generalist provides a promising step toward developing fully robust classifiers in the future.
title Generalist++: A Meta-learning Framework for Mitigating Trade-off in Adversarial Training
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2510.13361