PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 23, 2026IEEE Transactions on Image Processing0 citations

Robust Source-Free Domain Adaptation From Non-Robust Source Models

View Full Paper
YXYao XiaoPWPengxu WeiGWGuangrun Wang

Key Points

  • The aim is to explore the feasibility of training robust models on unlabeled target domains using non-robust source models.
  • Developed a Source-Free Alternating Optimization (SFAO) approach for model training.
  • Utilized a non-robust target model to guide adversarial training of the robust target model.
  • Implemented Softly-Constrained Adversarial Training (SCAT) to reduce negative impacts of incorrect labels.
  • Found that standard adversarial training leads to significant degradation when applied to self-supervised adaptation.
  • Demonstrated that SFAO improves model performance on both clean and adversarial datasets.

Abstract

A few recent works attempt to train an adversarially robust Unsupervised Domain Adaptation (UDA) model, transferring the robustness from a robust source model or other robust pre-trained models to an unlabeled target domain. However, it is usually impractical to assume the availability of robust source models or robust pre-training, and meanwhile, source data are not always accessible or efficient for adaptation training in many real-world scenarios. In this paper, we dive into a more practical and challenging problem of robust source-free domain adaptation: can we train a robust model on an unlabeled target domain given only a non-robust source model (without source data)? Empirically, we find that applying adversarial training (AT) to the self-supervised adaptation process leads to severe model degradation, as it tends to amplify the inevitable errors of UDA models. To tackle this issue, we propose a novel approach called Source-Free Alternating Optimization (SFAO), which employs a non-robust target model to provide better guidance for the AT of the desired robust target model. The two models are trained in an alternating manner to minimize the discrepancy between the clean source domain and the adversarial target domain. Moreover, we propose Softly-Constrained Adversarial Training (SCAT) to further mitigate the adverse effects of incorrect pseudo-labels in AT. Extensive experimental results demonstrate that the proposed method significantly improves the model performance on both clean and adversarial data. Source code is available at: https://github.com/Coxy7/robust-SFDA.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Xiao et al. (2026) studied this question.

synapsesocial.com/papers/699bee931c6c6bad539800bfhttps://doi.org/10.1109/tip.2026.3661392
Ask AI
Helpful
Bookmark
Share
View Full Paper