IJCAI 20260 citations

From Standard to Robust: A Universal Framework for Continual Adversarial Defense

Qian Wang, Hefei Ling, Yingwei Li, Qihao Liu, Ning Yu

Abstract

Continual adversarial defense (CAD) aims to defend target models against continuously emerging attacks. However, existing CAD methods typically rely on maintaining large amounts of replay data or multiple expert modules to mitigate catastrophic forgetting, or suffer from reduced robustness against adversarial examples or degraded performance on clean images. As a result, they often fail to provide clear advantages over standalone robust models. To address these limitations, we formulate four fundamental principles for CAD: (1) continual adaptation to new attacks without catastrophic forgetting, (2) few-shot adaptation, (3) memory-efficient adaptation, and (4) high classification accuracy on both clean and adversarial data. Guided by these principles, we explore and integrate cutting-edge techniques from continual learning, few-shot learning, and ensemble learning, and propose Universal Continual Adversarial Defense (UCAD), a universal framework that enables both standard and robust models to perform effective defense under the CAD setting. Extensive experiments validate the effectiveness of UCAD against multi-stage adversarial attacks and demonstrate significant improvements over a wide range of baseline methods. Moreover, we observe that as the number of encountered attacks increases, UCAD becomes increasingly robust, consistently enhancing the defense capability of existing robust models until saturation.

Machine Learning: Adversarial machine learningMachine Learning: ApplicationsMachine Learning: Few-shot learningMachine Learning: Incremental learning
BibTeX
@inproceedings{ijcai2026_fromstandardtoro,
  title = {From Standard to Robust: A Universal Framework for Continual Adversarial Defense},
  author = {Qian Wang and Hefei Ling and Yingwei Li and Qihao Liu and Ning Yu},
  booktitle = {IJCAI 2026},
  year = {2026}
}
From Standard to Robust: A Universal Framework for Continual Adversarial Defense · IJCAI 2026