Image Classification on ImageNet-1K 1.0 (test) (Robustness Evaluation)
83.9Accuracy (Clean)AdvXL (ViT-H/14)
Evaluation Results
| Method | Links | |||||
|---|---|---|---|---|---|---|
| AdvXL (ViT-H/14)Training Dataset=ImageNet-1K + DataComp-1B, Samples @ Resolution=5.12B@84 + 38.4M@224 + 6.4M@336, Pre-trained=false, Adv. Steps=2/3, Params (M)=304, Compute (1e10 GFLOPS)=39.62024.01 | 83.9 | 69.8 | 69.8 | 46 | — | |
| AdvXL (ViT-g/14)Training Dataset=ImageNet-1K + DataComp-1B, Samples @ Resolution=5.12B@84 + 38.4M@224 + 6.4M@336, Pre-trained=false, Adv. Steps=2/3, Params (M)=1013, Compute (1e10 GFLOPS)=63.42024.01 | 83.9 | 71 | 70.4 | 46.7 | — | |
| Swin-LTraining Dataset=ImageNet-1K, Samples @ Resolution=384M@224, Pre-trained=false, Adv. Steps=3, Params (M)=197, Compute (1e10 GFLOPS)=5.32024.01 | 78.9 | 59.6 | — | — | — | |
| ConvNeXt-L+ConvStemTraining Dataset=ImageNet-1K, Samples @ Resolution=128M@224 (320 eval), Pre-trained=true, Adv. Steps=3, Params (M)=198, Compute (1e10 GFLOPS)=1.82024.01 | 78.2 | 59.4 | 56.2 | 33.8 | — | |
| ConvNeXt-LTraining Dataset=ImageNet-1K, Samples @ Resolution=384M@224, Pre-trained=false, Adv. Steps=3, Params (M)=198, Compute (1e10 GFLOPS)=5.32024.01 | 78 | 58.5 | — | — | — | |
| ConvNeXt-L+ConvStemTraining Dataset=ImageNet-1K, Samples @ Resolution=128M@224, Pre-trained=true, Adv. Steps=3, Params (M)=198, Compute (1e10 GFLOPS)=1.82024.01 | 77 | 57.7 | 47 | 22.2 | — | |
| ViT-B/16Training Dataset=ImageNet-1K, Samples @ Resolution=384M@224, Pre-trained=false, Adv. Steps=2, Params (M)=87, Compute (1e10 GFLOPS)=2.72024.01 | 76.6 | 53.5 | — | — | — | |
| Swin-BTraining Dataset=ImageNet-1K, Samples @ Resolution=384M@224, Pre-trained=false, Adv. Steps=3, Params (M)=88, Compute (1e10 GFLOPS)=2.42024.01 | 76.2 | 56.2 | 47.9 | 23.9 | — | |
| ConvNeXT-BTraining Dataset=ImageNet-1K, Samples @ Resolution=384M@224, Pre-trained=false, Adv. Steps=3, Params (M)=89, Compute (1e10 GFLOPS)=2.42024.01 | 76 | 55.8 | 44.7 | 21.2 | — | |
| ConvNeXt-B+ConvStemTraining Dataset=ImageNet-1K, Samples @ Resolution=320M@224, Pre-trained=true, Adv. Steps=3, Params (M)=89, Compute (1e10 GFLOPS)=2.02024.01 | 75.2 | 56.3 | 49.4 | 23.6 | — | |
| Wang et al. (2022) + SSNI-NClassifier Backbone=RN-50, Attack Type=PGD+EOT l_infinity, Perturbation Budget (epsilon)=4/255, DBP Method=GDMP, Sample-Specific Noise Injection (SSNI-N)=true2025.06 | 75.07 | — | — | — | 5.21 | |
| Wang et al. (2022)Classifier Backbone=RN-50, Attack Type=PGD+EOT l_infinity, Perturbation Budget (epsilon)=4/255, DBP Method=GDMP, Sample-Specific Noise Injection (SSNI-N)=false2025.06 | 74.22 | — | — | — | 0.39 | |
| RobArch-LTraining Dataset=ImageNet-1K, Samples @ Resolution=128M@224, Pre-trained=false, Adv. Steps=3, Params (M)=104, Compute (1e10 GFLOPS)=1.32024.01 | 73.5 | 48.9 | 39.5 | 14.7 | — | |
| Lee & Kim (2023) + SSNI-NClassifier Backbone=RN-50, Attack Type=PGD+EOT l_infinity, Perturbation Budget (epsilon)=4/255, DBP Method=GNS, Sample-Specific Noise Injection (SSNI-N)=true2025.06 | 72.69 | — | — | — | 43.48 | |
| Nie et al. (2022) + SSNI-NClassifier Backbone=RN-50, Attack Type=PGD+EOT l_infinity, Perturbation Budget (epsilon)=4/255, DBP Method=DiffPure, Sample-Specific Noise Injection (SSNI-N)=true2025.06 | 70.25 | — | — | — | 33.66 | |
| Lee & Kim (2023)Classifier Backbone=RN-50, Attack Type=PGD+EOT l_infinity, Perturbation Budget (epsilon)=4/255, DBP Method=GNS, Sample-Specific Noise Injection (SSNI-N)=false2025.06 | 70.18 | — | — | — | 42.45 | |
| Nie et al. (2022)Classifier Backbone=RN-50, Attack Type=PGD+EOT l_infinity, Perturbation Budget (epsilon)=4/255, DBP Method=DiffPure, Sample-Specific Noise Injection (SSNI-N)=false2025.06 | 68.23 | — | — | — | 30.34 |