Papers › Adversarial Feature Augmentation and Normalization for Visual Recognition

Adversarial Feature Augmentation and Normalization for Visual Recognition

22 Mar 2021arXiv:2103.12171archive 2025-07-28

Tianlong Chen, Yu Cheng, Zhe Gan, JianFeng Wang, Lijuan Wang, Zhangyang Wang, Jingjing Liu

Recent advances in computer vision take advantage of adversarial data augmentation to ameliorate the generalization ability of classification models. Here, we present an effective and efficient alternative that advocates adversarial augmentation on intermediate feature embeddings, instead of relying on computationally-expensive pixel-level perturbations. We propose Adversarial Feature Augmentation and Normalization (A-FAN), which (i) first augments visual recognition models with adversarial features that integrate flexible scales of perturbation strengths, (ii) then extracts adversarial feature statistics from batch normalization, and re-injects them into clean features through feature normalization. We validate the proposed approach across diverse visual recognition tasks with representative backbone networks, including ResNets and EfficientNets for classification, Faster-RCNN for detection, and Deeplab V3+ for segmentation. Extensive experiments show that A-FAN yields consistent generalization improvement over strong baselines across various datasets for classification, detection and segmentation tasks, such as CIFAR-10, CIFAR-100, ImageNet, Pascal VOC2007, Pascal VOC2012, COCO2017, and Cityspaces. Comprehensive ablation studies and detailed analyses also demonstrate that adding perturbations to specific modules and layers of classification/detection/segmentation backbones yields optimal performance. Codes and pre-trained models will be made available at: https://github.com/VITA-Group/CV_A-FAN.

PaperPDFCodeCode Syntology ran

In Syntology Open this paper in Syntology's Atlas, the map of the papers in Syntology's graph and their citations.

For agents, Syntology's MCP tool lists every function and class Syntology harvested from this paper and whether it ran (how to connect): get_harvested_code_for_paper(arxiv_id="2103.12171")

Code

Syntology Ran 0 of 11 code samples harvested from 1 repository linked to this paper; 11 have no recorded run.

By repository: official repository: 11 samples from 1 repository, 0 ran. The run record, sample by sample. “Ran” means executed on a synthesized input, not that the code is correct or reproduces the paper.

VITA-Group/CV_A-FAN officialmentioned in paperpytorchMIT report

Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.

Code Syntology ran Syntology

11 samples harvested; 0 ran; 0 honoured the contract we drafted; 11 have no recorded run. Read from Syntology's graph 2026-09-24; that is when this build read the record, not when the samples ran.

11unverified

Licence: 0 of the 11 samples are pointer only, meaning Syntology does not serve that copy's text. This page shows no code text for any sample; each one links to its file in the repository.

Harvested from VITA-Group/CV_A-FAN. “Ran” means the sample executed on a synthesized input. It does not mean the output is correct, and nothing here reproduces the paper's results. “Honoured” and “violated” refer to a contract Syntology drafted from the code itself; “our draft was wrong” and “fixture could not drive it” are failures of Syntology's instrument, not of the code.

Each sample ends with its code_sha256, Syntology's identity for that exact code. An agent fetches the stored sample with Syntology's MCP tool get_code(code_sha256="…") (how to connect); click an identity to copy that call.

Repository labels, per sample. official repository: The archive marks this repository official for the paper. named in the paper: The archive records that the paper mentions this repository; it is not marked official. community (archive-listed): In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper. found in paper text by Syntology: Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted. community: Not in the archive's code links for this paper; a community repository Syntology harvested. Samples from a repository marked official are listed first. Licence labels name the repository's licence as recorded at harvest. “Pointer only” means Syntology does not serve that copy's text, for one of four reasons: no licence file was found; the licence was not identified; the licence is recorded as permissive but that copy's record is not marked cleared; or the licence is outside the permissive list Syntology serves text under (MIT, Apache-2.0, BSD and similar). Some licences outside that list permit redistribution, such as WTFPL, and GPL-3.0 under its conditions; they are simply not on the list. Hover a licence label for the reason. File links open the file on GitHub at the default branch, which may have changed since the harvest.

accuracy VITA-Group/CV_A-FAN/Classification/main_base.py official repository unverified MIT (permissive) · f0c9a29156911331 · report
cifar100_dataloaders VITA-Group/CV_A-FAN/Classification/dataset.py official repository unverified MIT (permissive) · accb544e928582b0 · report
cifar10_dataloaders VITA-Group/CV_A-FAN/Classification/dataset.py official repository unverified MIT (permissive) · 64da12f56f9679cb · report
compute_loss VITA-Group/CV_A-FAN/Detection/attack_algo.py official repository unverified MIT (permissive) · 435fe2f837c1215a · report
convert_dict VITA-Group/CV_A-FAN/Detection/model.py official repository unverified MIT (permissive) · e2455c4a931f470f · report
l2ball_proj VITA-Group/CV_A-FAN/Classification/attack_algo.py official repository unverified MIT (permissive) · 117dba8c37f0d0e2 · report
linfball_proj VITA-Group/CV_A-FAN/Classification/attack_algo.py official repository unverified MIT (permissive) · 0c047328d6d12286 · report
tensor_clamp VITA-Group/CV_A-FAN/Classification/attack_algo.py official repository unverified MIT (permissive) · 1e03c20ad26e5cae · report
train VITA-Group/CV_A-FAN/Classification/main_base.py official repository unverified MIT (permissive) · a21162e8545743de · report
validate VITA-Group/CV_A-FAN/Classification/main_base.py official repository unverified MIT (permissive) · ca240b92138d0b38 · report
validate VITA-Group/CV_A-FAN/Classification/main_learnable.py official repository unverified MIT (permissive) · e7e9d28918f9d793 · report

Tasks

ClassificationData AugmentationGeneral ClassificationSegmentation

Results from the paper archive 2025-07-28

No leaderboard rows for this paper in the archive.

Methods

CRFDeepLabDense ConnectionsDilated ConvolutionFeedforward Network

Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections