Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Hierarchically Robust Zero-shot Vision-language Models

About

Vision-Language Models (VLMs) can perform zero-shot classification but are susceptible to adversarial attacks. While robust fine-tuning improves their robustness, existing approaches align fixed text embeddings with an image embedding, sacrificing natural performance and robustness. A robustness degradation also occurs when a model faces adversarial attacks targeting superclasses (parent classes, e.g., mammal) in addition to their base (leaf) classes (e.g., cat). Thus, to enhance adversarial robustness and leverage the inherent hierarchical properties of class space, we propose a novel adversarial fine-tuning framework based on hierarchical embeddings and several levels of adversarially robust alignment of image-text modalities. Additional mechanisms place visual embeddings at the desired depth of hierarchy, and we provide a theoretical connection between the depth of embedding in the hierarchy and the maximum viable margin size. Our model naturally realizes several margin sizes, boosting generalization of adversaries for robustification. As various trees with different parent labels can share the same leaf labels, we also consider aligning over multiple trees to boost semantic variety. Experiments across several datasets are performed.

Junhao Dong, Yifei Zhang, Hao Zhu, Yew-Soon Ong, Piotr Koniusz• 2026

Related benchmarks

TaskDatasetResultRank
Image ClassificationCIFAR10
Accuracy (%)87.13
282
Image ClassificationCIFAR10--
143
Image ClassificationFood101
Robust Accuracy35.89
56
Image ClassificationPCAM
Robust Accuracy37.82
47
Image ClassificationOxfordPets
Robust Accuracy68.05
41
Image ClassificationCaltech-256
Clean Accuracy81.85
33
Image ClassificationStanford Cars
Top-1 Accuracy (Clean)48.23
29
Image ClassificationFGVC
Clean Accuracy17.76
23
Image ClassificationPCAM
Clean Accuracy51.69
23
Image ClassificationOxford Pets
Accuracy86.32
22
Showing 10 of 35 rows

Other info

Follow for update