{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/outlier-robust-adversarial-training","title":"Outlier Robust Adversarial Training","arxiv_id":"2309.05145","date":"2023-09-10","proceeding":null,"authors":["Shu Hu","Zhenhuan Yang","Xin Wang","Yiming Ying","Siwei Lyu"],"abstract":"Supervised learning models are challenged by the intrinsic complexities of training data such as outliers and minority subpopulations and intentional attacks at inference time with adversarial samples. While traditional robust learning methods and the recent adversarial training approaches are designed to handle each of the two challenges, to date, no work has been done to develop models that are robust with regard to the low-quality training data and the potential adversarial attack at inference time simultaneously. It is for this reason that we introduce Outlier Robust Adversarial Training (ORAT) in this work. ORAT is based on a bi-level optimization formulation of adversarial training with a robust rank-based loss function. Theoretically, we show that the learning objective of ORAT satisfies the $\\mathcal{H}$-consistency in binary classification, which establishes it as a proper surrogate to adversarial 0/1 loss. Furthermore, we analyze its generalization ability and provide uniform convergence rates in high probability. ORAT can be optimized with a simple algorithm. Experimental evaluations on three benchmark datasets demonstrate the effectiveness and robustness of ORAT in handling outliers and adversarial attacks. Our code is available at https://github.com/discovershu/ORAT.","url_abs":"https://arxiv.org/abs/2309.05145v1","url_pdf":"https://arxiv.org/pdf/2309.05145v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"outlier-robust-adversarial-training","repo_url":"https://github.com/discovershu/orat","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[{"task_slug":"adversarial-attack","task_name":"Adversarial Attack"},{"task_slug":"binary-classification","task_name":"Binary Classification"}],"methods":[{"method_slug":"rbl","method_name":"Rank-based Loss"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2309.05145","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2309.05145"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/discovershu/orat","reach":{"status":"ok"}}],"summary":{"unverified":5},"by_repo_kind":{"official":{"samples":5,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":5,"samples":[{"code_sha256_prefix":"fe7eaae3746b472c","entry":"cwloss","repo":"discovershu/orat","repo_kind":"official","path":"attack_generator.py","file_url":"https://github.com/discovershu/orat/blob/HEAD/attack_generator.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"fe7eaae3746b472c"}},{"code_sha256_prefix":"46dd15a24372e042","entry":"cwloss","repo":"discovershu/orat","repo_kind":"official","path":"attack_generator_for_cifar100.py","file_url":"https://github.com/discovershu/orat/blob/HEAD/attack_generator_for_cifar100.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"46dd15a24372e042"}},{"code_sha256_prefix":"f2807357177f7912","entry":"eval_clean","repo":"discovershu/orat","repo_kind":"official","path":"attack_generator.py","file_url":"https://github.com/discovershu/orat/blob/HEAD/attack_generator.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"f2807357177f7912"}},{"code_sha256_prefix":"2ea2c513cf37e3ab","entry":"pgd","repo":"discovershu/orat","repo_kind":"official","path":"attack_generator.py","file_url":"https://github.com/discovershu/orat/blob/HEAD/attack_generator.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"2ea2c513cf37e3ab"}},{"code_sha256_prefix":"0dd83d1a63902700","entry":"pgd","repo":"discovershu/orat","repo_kind":"official","path":"attack_generator_for_cifar100.py","file_url":"https://github.com/discovershu/orat/blob/HEAD/attack_generator_for_cifar100.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"0dd83d1a63902700"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}