Recent neural architecture search (NAS) frameworks have been successful in finding optimal architectures for given conditions (e.g., performance or latency). However, they search for optimal architectures in terms of their performance on clean images only, while robustness against various types of perturbations or corruptions is crucial in practice. Although there exist several robust NAS frameworks that tackle this issue by integrating adversarial training into one-shot NAS, however, they are limited in that they only consider robustness against adversarial attacks and require significant computational resources to discover optimal architectures for a single task, which makes them impractical in real-world scenarios. To address these challenges, we propose a novel lightweight robust zero-cost proxy that considers the consistency across features, parameters, and gradients of both clean and perturbed images at the initialization state. Our approach facilitates an efficient and rapid search for neural architectures capable of learning generalizable features that exhibit robustness across diverse perturbations. The experimental results demonstrate that our proxy can rapidly and efficiently search for neural architectures that are consistently robust against various perturbations on multiple benchmark datasets and diverse search spaces, largely outperforming existing clean zero-shot NAS and robust NAS with reduced search cost.
翻译:近年来,神经架构搜索(NAS)框架在给定条件(如性能或延迟)下寻找最优架构方面取得了成功。然而,这些框架仅根据模型在干净图像上的性能搜索最优架构,而实际应用中,模型对各类扰动或破坏的鲁棒性至关重要。尽管已有若干鲁棒NAS框架通过将对抗训练集成到单次NAS中来解决这一问题,但它们存在局限性:仅考虑对对抗攻击的鲁棒性,且需耗费大量计算资源才能为单一任务发现最优架构,这使其难以在真实场景中实际应用。为应对这些挑战,我们提出一种新型轻量级鲁棒零成本代理,该代理在初始化阶段同时考虑干净图像与扰动图像在特征、参数和梯度上的一致性。我们的方法能够高效、快速地搜索可学习通用特征且对多种扰动具有鲁棒性的神经架构。实验结果表明,我们的代理能够在多个基准数据集和多样搜索空间中快速高效地搜索到对各类扰动保持稳定鲁棒的神经架构,在降低搜索成本的同时,显著优于现有的干净零样本NAS和鲁棒NAS方法。