Our new X account is live! Follow @wizwand_team for updates
WorkDL logo mark

Contrastive Spectral Rectification: Test-Time Defense towards Zero-shot Adversarial Robustness of CLIP

About

Vision-language models (VLMs) such as CLIP have demonstrated remarkable zero-shot generalization, yet remain highly vulnerable to adversarial examples (AEs). While test-time defenses are promising, existing methods fail to provide sufficient robustness against strong attacks and are often hampered by high inference latency and task-specific applicability. To address these limitations, we start by investigating the intrinsic properties of AEs, which reveals that AEs exhibit severe feature inconsistency under progressive frequency attenuation. We further attribute this to the model's inherent spectral bias. Leveraging this insight, we propose an efficient test-time defense named Contrastive Spectral Rectification (CSR). CSR optimizes a rectification perturbation to realign the input with the natural manifold under a spectral-guided contrastive objective, which is applied input-adaptively. Extensive experiments across 16 classification benchmarks demonstrate that CSR outperforms the SOTA by an average of 18.1% against strong AutoAttack with modest inference overhead. Furthermore, CSR exhibits broad applicability across diverse visual tasks. Code is available at https://github.com/Summu77/CSR.

Sen Nie, Jie Zhang, Zhuo Wang, Shiguang Shan, Xilin Chen• 2026

Related benchmarks

TaskDatasetResultRank
Image ClassificationFlowers102
Clean Accuracy83.5
49
Image ClassificationStanfordCars
Clean Accuracy76.9
40
ClassificationPCAM
Clean Accuracy51
39
Image ClassificationCIFAR10
Clean Accuracy90.7
37
ClassificationFGVCAircraft
Robust Accuracy32.5
30
Image ClassificationOxfordPets
Robust Accuracy76.4
27
Image ClassificationCIFAR100
Clean Accuracy62.9
27
Image ClassificationFood101
Clean Accuracy90.6
25
Image ClassificationDomain-PCAM
Clean Accuracy45.6
20
Image ClassificationCountry211
Clean Accuracy23
20
Showing 10 of 44 rows

Other info

Follow for update