On robust overfitting: adversarial training induced distribution matters
Runzhi Tian, Yongyi Mao
OpenReview ground truth
Abstract
Robust overfitting has been observed to arise in adversarial training. We hypothesize that this phenomenon may be related to the evolution of the data distribution along the training trajectory. To investigate this, we select a set of checkpoints in adversarial training and perform standard training on distributions induced by adversarial perturbation w.r.t the checkpoints. We observe that the obtained models become increasingly harder to generalize when robust overfitting occurs, thereby validating the hypothesis. We show the hardness of generalization on the induced distributions is related to certain local properties of the perturbation operator at each checkpoint. This local property is characterized by a quantity defined as local dispersion in our work. The connection between the local dispersion and the generalization on the induced distribution is proved by establishing an upper bound of the generalization error.
Author context
Most prolific author: 2 submissions (credibility 1.00).
No mass-submission penalty for this paper (authors within normal submission volume).
Aggregate statistics only — no individual author rankings.
Ranking trajectory
Percentile by tournament round — convergence indicates rating stability.
Battle history — 38 comparisons
Ranked above opponent in 54% of matchups.
- ▲ beat BWS: Best Window Selection Based on Sample… ×8
- ▼ lost to Rethinking Self-Supervise Learning: An Ins… ×6
- ▲ beat Safeguarding Data in Multimodal AI: A Diff… ×4
- ▼ lost to A Recipe for Improved Certifiable Robustne… ×4
- ▲ beat Black-box Targeted Adversarial Attack on S… ×4
Judge assessments
Mean overall score 0.0 ± 0.0 (n = 38)