Unsupervised Robust Domain Adaptation: Paradigm, Theory and Algorithm

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Huang, Fuxiang, Fu, Xiaowei, Ye, Shiyu, Ma, Lina, Li, Wen, Gao, Xinbo, Zhang, David, Zhang, Lei
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866911265778040832
author Huang, Fuxiang
Fu, Xiaowei
Ye, Shiyu
Ma, Lina
Li, Wen
Gao, Xinbo
Zhang, David
Zhang, Lei
author_facet Huang, Fuxiang
Fu, Xiaowei
Ye, Shiyu
Ma, Lina
Li, Wen
Gao, Xinbo
Zhang, David
Zhang, Lei
contents Unsupervised domain adaptation (UDA) aims to transfer knowledge from a label-rich source domain to an unlabeled target domain by addressing domain shifts. Most UDA approaches emphasize transfer ability, but often overlook robustness against adversarial attacks. Although vanilla adversarial training (VAT) improves the robustness of deep neural networks, it has little effect on UDA. This paper focuses on answering three key questions: 1) Why does VAT, known for its defensive effectiveness, fail in the UDA paradigm? 2) What is the generalization bound theory under attacks and how does it evolve from classical UDA theory? 3) How can we implement a robustification training procedure without complex modifications? Specifically, we explore and reveal the inherent entanglement challenge in general UDA+VAT paradigm, and propose an unsupervised robust domain adaptation (URDA) paradigm. We further derive the generalization bound theory of the URDA paradigm so that it can resist adversarial noise and domain shift. To the best of our knowledge, this is the first time to establish the URDA paradigm and theory. We further introduce a simple, novel yet effective URDA algorithm called Disentangled Adversarial Robustness Training (DART), a two-step training procedure that ensures both transferability and robustness. DART first pre-trains an arbitrary UDA model, and then applies an instantaneous robustification post-training step via disentangled distillation.Experiments on four benchmark datasets with/without attacks show that DART effectively enhances robustness while maintaining domain adaptability, and validate the URDA paradigm and theory.
format Preprint
id arxiv_https___arxiv_org_abs_2511_11009
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Unsupervised Robust Domain Adaptation: Paradigm, Theory and Algorithm
Huang, Fuxiang
Fu, Xiaowei
Ye, Shiyu
Ma, Lina
Li, Wen
Gao, Xinbo
Zhang, David
Zhang, Lei
Machine Learning
Computer Vision and Pattern Recognition
Unsupervised domain adaptation (UDA) aims to transfer knowledge from a label-rich source domain to an unlabeled target domain by addressing domain shifts. Most UDA approaches emphasize transfer ability, but often overlook robustness against adversarial attacks. Although vanilla adversarial training (VAT) improves the robustness of deep neural networks, it has little effect on UDA. This paper focuses on answering three key questions: 1) Why does VAT, known for its defensive effectiveness, fail in the UDA paradigm? 2) What is the generalization bound theory under attacks and how does it evolve from classical UDA theory? 3) How can we implement a robustification training procedure without complex modifications? Specifically, we explore and reveal the inherent entanglement challenge in general UDA+VAT paradigm, and propose an unsupervised robust domain adaptation (URDA) paradigm. We further derive the generalization bound theory of the URDA paradigm so that it can resist adversarial noise and domain shift. To the best of our knowledge, this is the first time to establish the URDA paradigm and theory. We further introduce a simple, novel yet effective URDA algorithm called Disentangled Adversarial Robustness Training (DART), a two-step training procedure that ensures both transferability and robustness. DART first pre-trains an arbitrary UDA model, and then applies an instantaneous robustification post-training step via disentangled distillation.Experiments on four benchmark datasets with/without attacks show that DART effectively enhances robustness while maintaining domain adaptability, and validate the URDA paradigm and theory.
title Unsupervised Robust Domain Adaptation: Paradigm, Theory and Algorithm
topic Machine Learning
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2511.11009