[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125328-en":3,"doc-seo-125328-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125328,962075114765,"Quinn","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Robustness-Congruent Adversarial Training for Secure Machine Learning Model Updates","Machine-learning systems require frequent updates to improve average accuracy using new architectures and data, but updated models can introduce mistakes unseen in the previous version. Such sample-wise errors, termed negative flips, reduce perceived performance and can also undermine security against adversarial examples. This work shows that efforts to enhance adversarial robustness may unintentionally enable previously ineffective attacks, leading to security regressions. A robustness-congruent adversarial training method fine-tunes with constraints to preserve higher robustness on inputs where no adversarial example was found pre-update.","This article has been accepted for publication in IEEE Transactions on Pattern Analysis and Machine Intelligence. This is the author's version which has not been fully edited and content may change prior to final publication. Citation information: DOI 10. 1109/TPAMI.2025.3573237  \nJOURNAL OF LATEX CLASS FILES, VOL. 18, NO. 9, SEPTEMBER 2020 1  \nRobustness-Congruent Adversarial Training for Secure Machine Learning Model Updates  \nDaniele Angioni1, Luca Demetrio2, Maura Pintor1, Luca Oneto2, Davide Anguita, Senior Member, IEEE 2,  \nBattista Biggio, Fellow, IEEE1, and Fabio Roli, Fellow, IEEE1,2  \n1Department of Electrical and Electronic Engineering, University of Cagliari, Italy  \n2Department of Informatics, Bioengineering, Robotics and Systems Engineering, University of Genova, Italy  \nAbstract—Machine-learning models demand periodic updates to improve their average accuracy, exploiting novel architectures and additional data. However, a newly-updated model may commit mistakes that the previous model did not make. Such misclassifications are referred to as negative flips, experienced by users as a regression of performance. In this work, we show that this problem also affects robustness to adversarial examples, hindering the development of secure model update practices. In particular, when updating a model to improve its adversarial robustness, previously-ineffective adversarial attacks on some inputs may become successful, causing a  \nregression in the perceived security of the system. We propose a novel technique, named robustness-congruent adversarial training, to  \naddress this issue. It amounts to fine-tuning a model with adversarial training, while constraining it to retain higher robustness on the  \nsamples for which no adversarial example was found before update. We show that our algorithm and, more generally, learning with non-regression constraints, provides a theoretically-grounded framework to train consistent estimators. Our experiments on robust models for computer vision confirm that both accuracy and robustness, even if improved after model update, can be affected by negative flips, and our robustness-congruent adversarial training can mitigate the problem, outperforming competing baseline methods.  \nIndex Terms—Machine Learning, Adversarial Robustness, Adversarial Examples, Regression Testing  \n~~ ~~ ✦ ~~ ~~  \n1 INTRODUCTION  \nMany modern applications of machine learning require frequent model updates to keep pace with the introduction of novel and more powerful architectures, as well as with changes in the underlying data distribution. For instance, when dealing with cybersecurity-related tasks like malware detection, novel threats are discovered at a high pace, and machine learning models need to be constantly retrained to learn to detect them with high accuracy. Another example is given by image tagging, in which image classification and detection models are used to tag pictures of users, and the variety of depicted objects and scenarios varies over time, requiring constant updates. In both cases, as novel and more powerful machine learning architectures emerge, they are rapidly adopted to improve the average system performance; consider, for instance, the need for transitioning from convolutional neural networks to transformer-based architectures.  \nWithin the aforementioned scenarios, the practice of delivering frequent model updates opens up a new challenge related to the maintenance of machine learning models and their performance as perceived by the end users. The issue is that average accuracy is not elaborate enough to also account for sample-wise performance. In particular, even if average accuracy increases after update, some samples that were correctly predicted by the previous model might be misclassified after model update. There is indeed no guarantee that a newly-updated model with higher average accuracy  \nwill not commit any mistake on the samples that were correctly predicted by the previous","cbCaidrSJ0PeugwC","https://ap.wps.com/l/cbCaidrSJ0PeugwC","pdf",3806513,1,13,"English","en",105,"# Introduction\n## Negative flips in model updates\n## Adversarial robustness regression\n# Proposed method\n## Robustness-congruent adversarial training\n# Experiments\n## Results on computer vision robustness and accuracy","[{\"question\":\"What are negative flips in machine learning model updates?\",\"answer\":\"Negative flips are cases where the updated model misclassifies samples that were correctly predicted by the previous model. They cause a regression in user-perceived performance.\"},{\"question\":\"How can improving adversarial robustness lead to security regression?\",\"answer\":\"When updating for better adversarial robustness, attacks that were previously ineffective on some inputs may become successful. This creates a regression in the system’s perceived security.\"},{\"question\":\"What is robustness-congruent adversarial training?\",\"answer\":\"It fine-tunes a model using adversarial training while constraining it to retain higher robustness for samples where no adversarial example was found before the update.\"}]","Robustness-Congruent Adversarial Training for Secure Machine Learning Model Updates | PDF",1785898204,33,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"robustness-congruent-adversarial-training-for-secure-machine-learning-model-updates","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/robustness-congruent-adversarial-training-for-secure-machine-learning-model-updates/125328/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What are negative flips in machine learning model updates?","Question",{"text":75,"@type":76},"Negative flips are cases where the updated model misclassifies samples that were correctly predicted by the previous model. They cause a regression in user-perceived performance.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How can improving adversarial robustness lead to security regression?",{"text":80,"@type":76},"When updating for better adversarial robustness, attacks that were previously ineffective on some inputs may become successful. This creates a regression in the system’s perceived security.",{"name":82,"@type":73,"acceptedAnswer":83},"What is robustness-congruent adversarial training?",{"text":84,"@type":76},"It fine-tunes a model using adversarial training while constraining it to retain higher robustness for samples where no adversarial example was found before the update.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]