RDA: Robust Domain Adaptation via Fourier Adversarial Attacking

Jiaxing Huang, Dayan Guan, Aoran Xiao, Shijian Lu

Introduction

Deep convolutional neural networks (CNNs) have defined new state of the arts in various computer vision tasks , but their trained models often over-fit to the training data and experience clear performance drops for data from different sources due to the existence of domain gaps. Unsupervised domain adaptation (UDA) has been investigated to address the domain gaps by leveraging unlabeled target data. To this end, most existing UDA works involve supervised losses on source data and unsupervised losses on target data for learning a model that performs well in target domains. However, as illustrated in Fig. 1, these methods often face more severe overfitting (as compared with the classical supervised learning) as supervised source losses in UDA has an extra domain gap (for test data in target domains) and unsupervised target losses are often noisy due to the lack of annotations.

Overfitting exists in almost all deep network training, which is undesired and often degrades the generalization of the trained deep network models while applied to new data. One way of identifying whether overfitting is happening is to check whether the generalization gap, i.e., the difference between the test loss and the training loss, is increasing or not as shown in Fig. 1. Various strategies have been investigated to alleviate overfitting through weight regularization , dropout , mixup , label smoothing , batch normalization , etc. However, all these strategies were designed for supervised and semi-supervised learning where training data and test data usually have very similar distributions. For domain adaptive learning, they do not fit in well due to the negligence of domain gaps that widely exist between data of different domains.

We design a robust domain adaptation technique that introduces a novel Fourier adversarial attacking (FAA) technique to mitigate the overfitting in unsupervised domain adaptation. FAA mitigates overfitting by generating adversarial samples that prevent over-minimization of supervised and unsupervised UDA losses as illustrated in Fig. 1. Specifically, FAA decomposes training images into multiple frequency components (FCs) and only perturbs FCs that capture little semantic information. Unlike traditional attacking that restricts the magnitude of perturbation noises to keep image semantics intact, FAA allows large magnitude of perturbation in its generated adversarial samples but has minimal modification of image semantics. This feature is critical to unsupervised domain adaptation which usually involves clear domain gaps and so requires adversarial sample with large perturbations. By introducing the FAA-generated adversarial samples in training, networks can continue the “random walk” and avoid over-fitting and drift into an area with a flat loss landscape , leading to more robust domain adaptation.

The contributions of this work can be summarized in three aspects. First, we identify the overfitting issue in unsupervised domain adaptation and introduce adversarial attacking to mitigate overfitting by preventing training objectives from over-minimization. Second, we design an innovative Fourier Adversarial Attacking (FAA) technique to generate novel adversarial samples to mitigate overfitting in domain adaptation. FAA is generic which can work for both supervised source loss and unsupervised target losses effectively. Third, we conducted extensive experiments over multiple computer vision tasks in semantic segmentation, object detection and image classification. All experiments show that our method mitigates overfitting and improve domain adaption consistently.

Related Works

Domain Adaptation: Domain adaptation has been studied extensively for mitigating data annotation constraints. Most existing works can be broadly classified into three categories. The first category is adversarial training based which employs a discriminator to align source and target domains in the feature, output or latent space . The second category is image translation based which adapt image appearance to mitigate domain gaps . The third category is self-training based which predict pseudo labels or minimize entropy to guide iterative learning from target samples .

Domain adaptation involves two typical training losses, namely, supervised loss over labeled source data and unsupervised loss over unlabeled target data. State-of-the-art methods tend to over-minimize the two types of losses which directly leads to deviated models with suboptimal adaptation as illustrated in Fig. 1. We design a robust domain adaptation technique that addresses this issue by preventing loss over-minimization.

Overfitting in Network Training: Overfitting is a common phenomenon in deep network training which has been widely studied in the deep learning and computer vision community . Most existing works address overfitting by certain regularization strategies such as weight decay , dropout , l1l_{1} regularization , mix-up , label smoothing , batch normalization , virtual adversarial training , flooding , etc. However, these strategies were mostly designed for supervised or semi-supervised learning which do not fit in well for domain adaptive learning that usually involves domain gaps and unsupervised losses. We design a adversarial attacking technique that mitigates the overfitting in domain adaptive learning effectively.

Adversarial Attacking: Adversarial attacking has been studied in various security problems. For example, shows that adversarial samples can easily confuse CNN models. The following works improved adversarial attacking from different aspects via fast gradient signs , minimal adversarial perturbation , universal adversarial perturbations , gradient-free attacking , transferable adversarial sample generation, etc. Adversarial attacking has also been applied to other tasks, e.g., employed adversarial samples to mitigate over-fitting in supervised and semi-supervised learning, generated adversarial samples for data augmentation, and augments transferable features for domain divergence minimization.

Most existing adversarial attacking methods commonly constrain the magnitude of perturbation noises for minimal modification of image semantics. However, such generated adversarial samples cannot tackle overfitting in domain adaptive learning well which usually involves a domain gap of fair magnitude. We design an innovative Fourier adversarial attacking technique that allows to generate adversarial samples without magnitude constraint yet with minimal modification of image semantics, more details to be described in the ensuing subsections.

Method

We achieve robust domain adaptation via Fourier adversarial attacking as illustrated in Fig. 2. The training consists of two phases, namely, an Attacking Phase and a Defending Phase. Given a training image, the attacking phase learns to identify the right FCs with limited semantic information that allow perturbation noises of large magnitude. It also learns to generate adversarial samples (with perturbable FCs) with minimal modification of image semantics. During the defending phase, the generated adversarial sample is applied to mitigate overfitting by preventing over-minimization of training losses, more details to be described in the ensuing subsections.

We focus on the problem of unsupervised domain adaptation (UDA). Given labeled source data {XsX_{s}, YsY_{s}} and unlabeled target data XtX_{t}, our goal is to learn a task model FF that performs well on XtX_{t}. The baseline model is trained with the labeled source data only:

where l(⋅)l(\cdot) denotes an accuracy-related loss, e.g., the standard cross-entropy loss.

2 Fourier Adversarial Attacking

Our proposed Fourier adversarial attacking (FAA) generates adversarial samples to attack the training loss to mitigate overfitting in domain adaptation, as shown in Fig. 2. In adversarial sample generation, it first employs Fourier transformation to decompose input images into multiple frequency components (FCs) and then inject perturbation to non-semantic FCs which allows perturbation of large magnitude but with minimal modification of image semantics.

Fourier Decomposition: Inspired by JPEG and frequency-domain learning , we transform an image xx into frequency space and decompose it into multiple FCs which allows explicit manipulation of each FC and more controllable perturbations. We employ Fourier transformation to convert xx into frequency space and further decompose it into multiple FCs of equivalent bandwidth:

where F(⋅)\mathcal{F}(\cdot) stands for Fourier transformation ; zz denotes the frequency-space representation of xx; D(z;N)\mathcal{D}(z;N) denotes a function that decomposes zz into NN FCs zfc={z1,z2,...,zN−1,zN}z^{fc}=\{z^{1},z^{2},...,z^{N-1},z^{N}\} of equivalent bandwidth.

where d(⋅,⋅)d(\cdot,\cdot) denotes Euclidean distance, NN denotes how many FCs the input is supposed to be decomposed into and nn denotes the FC index.

Adversarial Attacking: With the decomposed FCs zfc={z1,z2,...,zN−1,zN}z^{fc}=\{z^{1},z^{2},...,z^{N-1},z^{N}\}, we attack domain adaption losses by perturbing partial FCs without magnitude constraint. Specifically, we employ a learnable gate module to select certain FCs for perturbation. This gate GG assigns a binary score to each FC, where ‘1’ indicates this FC is selected for perturbation (multiplied by ‘1’) while ‘0’ shows this FC is discarded (reset to all zero values). GG works with Gumbel-Softmax, a differentiable sampling mechanism for categorical variables that can be trained via standard back-propagation. Please refer to for details.

Given a reference image (an randomly selected target-domain image) in FC representation zreffc={zref1,zref2,...,zrefN−1,zrefN}=D(F(xref);N)z^{fc}_{ref}=\{z^{1}_{ref},z^{2}_{ref},...,z^{N-1}_{ref},z^{N}_{ref}\}=\mathcal{D}(\mathcal{F}(x_{ref});N), we employ this gate module to block some FCs (all reset to zero), and apply the selected FCs to perturb the corresponding FCs of the input image xx:

where the learnable gate module GG enables binary channel attention that selects which FCs to perturb.

Specifically, for the identified FCs of the input image xx, we extract the corresponding FCs of a reference image XrefX_{ref} and use them as perturbation noises. We generate adversarial samples in this manner because the perturbation noises (i.e., non-semantic FCs of zreffcz^{fc}_{ref}) from target natural images are more reasonable and meaningful as compared to a random noises/signals as in many existing adversarial sample generation methods. In addition, the use of non-semantic FCs of target samples mitigates inter-domain gaps which helps to improve target-domain performance in domain adaptation.

With the perturbed FCs z^fc\hat{z}^{fc}, we convert them all back (via inverse Fourier transformation) to get the adversarial sample xFAAx^{FAA}:

where C(⋅)\mathcal{C}(\cdot) denotes an inverse process of D(⋅;N)\mathcal{D}(\cdot;N) that ‘compose’ the decomposed zfcz^{fc} back to the full representation by summing all the elements over frequency channels.

The Fourier Decomposition and Adversarial Attacking can be combined to form the FAA as follows:

where A\mathcal{A} takes an image xx and outputs an adversarial sample xFAAx^{FAA} via the FAA as described. A\mathcal{A} has two sub-modules with learnable parameters, i.e.i.e., the gate module GG and the single-layer neural network for spatial weighting map S\mathcal{S} generation. The rest operations in A\mathcal{A} are deterministic such as Fourier transformation and its inverse (F(⋅)\mathcal{F}(\cdot) and F−1(⋅)\mathcal{F}^{-1}(\cdot)), decomposition and re-composition (D(⋅;N)\mathcal{D}(\cdot;N) and C(⋅)\mathcal{C}(\cdot))

3 FAA Training

The proposed FAA involves three types of losses including task loss (i.e., UDA training loss in this work) that is to be attacked, the gate related loss that constrains the proportion of perturbable FCs, and the reconstruction loss that aims to minimize the attacking effects over image semantics.

where G(zfc)G(z^{fc}) is a gating process in A\mathcal{A} as described in Eq. 2. RR is a band-pass filter to get the mid-frequency content that captures semantic information (e.g.e.g., structures and shapes) and thus the consistency loss can ensure that the selected FCs contains minimal semantic information. pp is a hyper-parameter that constrains the maximum number of perturbable FCs by N∗pN*p.

The overall training objective of FAA is formulated by:

4 Robust Domain Adaptation

Sections 3.2 and 3.3 describe the “Attacking Phase” that generates adversarial samples via FAA. This section presents the proposed robust domain adaptation technique where FAA is used to mitigate the overfitting in UDA in a “Defending Phase”. Specifically, we apply the FAA-generated adversarial samples to prevent the over-minimization of UDA training losses in domain adaptation.

Given the task model FF and the Fourier attacker A\mathcal{A}, the training objective of the task model FF is formulated by:

The optimization functions of both attacking (i.e., Eq. 5) and defending (i.e., Eq. 6) are generic and applicable to various tasks and data. Specifically, the model FF could be for semantic segmentation, object detection or image classification task. The data could be labeled source data with supervised source losses or unlabeled target data with unsupervised target losses such as adversarial loss , self-training loss or entropy loss , etc. Below are a supervised loss and a self-training-based unsupervised loss here for reference:

where l(⋅)l(\cdot) denotes an accuracy-related loss, e.g., cross entropy loss; A(Xs)\mathcal{A}(X_{s}) and A(Xt)\mathcal{A}(X_{t}) are inputs perturbed by FAA, and Y^t\hat{Y}_{t} is the pseudo label of unlabeled target data.

In summary, our robust domain adaptation has a bidirectional training framework including an Attacking Phase and a Defending Phase as shown in Fig. 2. In the Attacking Phase, the task model FF is fixed and the attacker A\mathcal{A} generates adversarial samples to increase the training loss. In the Defending Phase, A\mathcal{A} is fixed and FF is updated to reduce the training loss. These two phases are conducted in an alternative way way and form a bidirectional training framework (adversarial training). Please refer to Algorithm 1 for details.

This bidirectional training framework uses FAA to prevent over-minimization of UDA losses by forcing them oscillating around a small value. In another word, it ensures that the task model FF can continue the “random walk” and drift into an area with a flat loss landscape , leading to robust domain adaptation.

Experiments

This section presents experiments including datasets and implementation details, domain adaptation for semantic segmentation (with ablation studies), object detection, and image classification tasks, and discussion, more details to be described in the ensuing subsections.

Adaptation for semantic segmentation: We consider two synthesized-to-real segmentation tasks: 1) GTA5 →\rightarrow Cityscapes and 2) SYNTHIA →\rightarrow Cityscapes. GTA5 contains 24,96624,966 synthetic images and shares 1919 categories with Cityscapes. For SYNTHIA, we use ‘SYNTHIA-RAND-CITYSCAPES’ which contains 9,4009,400 synthetic images and shares 16 categories with Cityscapes. Cityscapes contains 29752975/500500 training/validation images. Following , we adapt towards the Cityscapes training set and evaluate on the Cityscapes validation set.

Adaptation for object detection: We consider two adaptation tasks: 1) Cityscapes →\rightarrow Foggy Cityscapes and 2) Cityscapes →\rightarrow BDD100k . For Cityscapes, we convert instance segmentation annotations to bounding boxes in experiments. Foggy Cityscapes was created by applying synthetic fog on Cityscapes images. BDD100k contains 100k100k images including 70k70k for training and 10k10k for validation. Following , we use a BDD100k subset daytime in experiments, which includes 36,72836,728 training images and 5,2585,258 validation images.

Adaptation for image classification: We adopt two adaptation benchmarks VisDA17 and Office-31 . VisDA17 includes 152,409152,409 synthetic images of 1212 categories as source and 55,40055,400 real images as target. Office-31 contains images of 3131 classes from Amazon (A), Webcam (W) and DSLR (D) that have 28172817, 795795 and 498498 images, respectively. We evaluate on six tasks A→\rightarrowW, D→\rightarrowW, W→\rightarrowD, A→\rightarrowD, D→\rightarrowA, and W→\rightarrowA as in .

2 Implementation Details

Semantic segmentation: We use DeepLab-V2 with ResNet101 as the segmentation network as in . We use SGD optimizer with a momentum 0.90.9 and a weight decay 1e−41e-4. The initial learning rate is 2.5e−42.5e-4 and decayed by a polynomial policy of power 0.90.9 .

Object detection: As in , we use Faster R-CNN with VGG-16 as the detection network. We use SGD optimizer with a momentum 0.90.9 and a weight decay 5e−45e-4. The initial learning rate is 1e−31e-3 for 50k50k iterations and reduced to 1e−41e-4 for another 20k20k iterations . In all experiments, we set image shorter side to 600 and employ RoIAlign for feature extraction.

Image classification: For fair comparisons, we follow and use ResNet-101/ResNet-50 (pre-trained with ImageNet ) as backbones. We use SGD optimizer with a momentum 0.90.9 and a weight decay 5e−45e-4. The learning rate is 1e−31e-3 and the batch size is 3232 .

We set the parameter pp and the number of FCs NN at 0.10.1 and 9696. The band-pass filter RR follows with mid-pass and low-/high-rejected designs to get the mid-frequency content that captures semantic information (e.g., structures and shapes).

3 Domain Adaptive Semantic Segmentation

Table 1 shows experimental results over semantic segmentation task GTA5 →\rightarrow Cityscapes. It can be seen that FAA is generic and can be applied to attack both Baseline (for preventing overfitting in supervised source loss) and state-of-the-art UDA methods (for preventing overfitting in both supervised source loss and unsupervised target loss). In addition, incorporating FAA improves both Baseline and UDA methods clearly and consistently.

We perform ablation studies over two representative UDA methods using adversarial alignment and self-training , where +FAA-S, +FAA-T and +FAA address the overfitting of supervised source losses, unsupervised target losses and both losses, respectively. It can be seen that +FAA-S and +FAA-T both improve domain adaptation by large margins. This shows that both supervised source objective and unsupervised target objective introduce clear overfitting and FAA mitigates the overfitting effectively. In addition, +FAA performs clearly the best. This shows that preventing the two learning objectives from over-minimization is complementary as overftting in the two learning objectives affects generalization in different manners. Specifically, supervised source loss has domain gap and over-minimizing it guides the model to over-memorize source data whereas unsupervised target loss is noisy and over-minimizing it leads to deviated solutions with accumulated errors.

Table 2 shows experimental results over semantic segmentation task SYNTHIA →\rightarrow Cityscapes. We can observe that FAA improves state-of-the-art UDA methods in the similar manner as in Table 1. Note we applied FAA to a few representative UDA methods only due to space limit.

4 Domain Adaptive Object Detection

Table 3 shows domain adaptive object detection over the task Cityscapes →\rightarrow Foggy Cityscapes. It can be seen that FAA boosts mAP by over +2.5%+2.5\% for both SWDA and CRDA . Note that we did not apply FAA to other listed UDA methods due to space limit.

Table 4 shows domain adaptive object detection over the task Cityscapes →\rightarrow BDD100k. It can be seen that including FAA outperforms state-of-the-art UDA methods consistently as in Table 3. Note that we did not apply FAA to other listed UDA methods due to space limit.

5 Domain Adaptive Image Classification

We presents experimental results on VisDA17 in Table 5 in per-class accuracy. It can be seen that incorporating FAA outperforms state-of-the-art UDA methods consistently. This applies to UDA methods that employ stronger backbones ResNet-152 .

Table 6 shows domain adaptive image classification experiments over Office-31 (all using the same backbone ResNet-50). We can see that incorporating FAA leads to robust domain adaptation and improve the image classification consistently by large margins.

6 Discussion

Qualitative illustration of domain adaptation in segmentation

We compare our robust domain adaptation (RDA) with the recent domain adaptation method qualitatively over semantic segmentation task. As Fig. 3 shows, the proposed RDA outperforms the baselines clearly.

Overfitting Mitigation: We compared FAA with existing overfitting mitigation methods. Most existing methods address overfitting through certain network regularization by noise injection to hidden units (Dropout), label-dropout (Label smooth), gradient ascent (Flooding), data and label mixing (Mixup), gradient based adversarial attacking (FGSM), virtual-label based adversarial attacking (VAT), etc. Table 7 shows experimental results over the task GTA→\rightarrowCityscapes. It can be seen that existing regularization does not perform well in the domain adaptation task. The major reason is that existing methods were designed for supervised and semi-supervised learning where training and test data usually have little domain gap. The proposed FAA mitigates overfitting with clear performance gains as it allows large magnitude of perturbation noises which is critical to the effectiveness of its generated adversarial samples due to the existence of ‘domain gaps’ in UDA.

Due to the space limit, we provide more visualization of the qualitative segmentation examples (including their comparisons with the recent domain adaptation method ) in the supplementary material.

Conclusion

In this work, we presented RDA, a robust domain adaptation technique that mitigates overfitting in UDA via a novel Fourier adversarial attacking (FAA). We achieve robust domain adaptation by a novel Fourier adversarial attacking (FAA) method that allows large magnitude of perturbation noises but has minimal modification of image semantics. With FAA-generated adversarial samples, the training can continue the ‘random walk’ and drift into an area with a flat loss landscape, leading to more robust domain adaptation. Extensive experiments over multiple domain adaptation tasks show that RDA can work with different computer vision tasks (i.e., segmentation, detection and classification) with superior performance. We will explore disentanglement-based adversarial attacking and its applications to other computer vision tasks. We will also study how FAA could mitigate over-fitting in classical supervised learning and semi-supervised learning as well as the recent contrast-based unsupervised representation learning.

Acknowledgement

This study is supported under the RIE2020 Industry Alignment Fund – Industry Collaboration Projects (IAF-ICP) Funding Initiative, as well as cash and in-kind contribution from Singapore Telecommunications Limited (Singtel), through Singtel Cognitive and Artificial Intelligence Lab for Enterprises (SCALE@NTU).

References