{"id":"https://openalex.org/W7125904571","doi":"https://doi.org/10.48550/arxiv.2601.19210","title":"Contrastive Spectral Rectification: Test-Time Defense towards Zero-shot Adversarial Robustness of CLIP","display_name":"Contrastive Spectral Rectification: Test-Time Defense towards Zero-shot Adversarial Robustness of CLIP","publication_year":2026,"publication_date":"2026-01-27","ids":{"openalex":"https://openalex.org/W7125904571","doi":"https://doi.org/10.48550/arxiv.2601.19210"},"language":null,"primary_location":{"id":"pmh:doi:10.48550/arxiv.2601.19210","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"publisher-specific-oa","license_id":"https://openalex.org/licenses/publisher-specific-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":null,"any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5124072945","display_name":"Sen Nie","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Nie, Sen","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124134949","display_name":"Jie M. Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Jie","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124120662","display_name":"Zhuo Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Zhuo","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124109700","display_name":"Shiguang Shan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shan, Shiguang","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5124099256","display_name":"Xilin Chen","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chen, Xilin","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5124072945"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9943000078201294,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9943000078201294,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.0008999999845400453,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.000699999975040555,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.73580002784729},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6929000020027161},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.6114000082015991},{"id":"https://openalex.org/keywords/rectification","display_name":"Rectification","score":0.5615000128746033},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.32600000500679016},{"id":"https://openalex.org/keywords/identifiability","display_name":"Identifiability","score":0.3073999881744385}],"concepts":[{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.73580002784729},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6929000020027161},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6753000020980835},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.6114000082015991},{"id":"https://openalex.org/C50942859","wikidata":"https://www.wikidata.org/wiki/Q4967193","display_name":"Rectification","level":3,"score":0.5615000128746033},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5231000185012817},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3614000082015991},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.32600000500679016},{"id":"https://openalex.org/C122770356","wikidata":"https://www.wikidata.org/wiki/Q1656753","display_name":"Identifiability","level":2,"score":0.3073999881744385},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3068999946117401},{"id":"https://openalex.org/C2983787585","wikidata":"https://www.wikidata.org/wiki/Q93586","display_name":"Feature matching","level":3,"score":0.28870001435279846},{"id":"https://openalex.org/C59404180","wikidata":"https://www.wikidata.org/wiki/Q17013334","display_name":"Feature learning","level":2,"score":0.2874999940395355},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.2754000127315521},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.2687999904155731},{"id":"https://openalex.org/C195324797","wikidata":"https://www.wikidata.org/wiki/Q33742","display_name":"Natural language","level":2,"score":0.2644999921321869},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.26190000772476196}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:doi:10.48550/arxiv.2601.19210","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"publisher-specific-oa","license_id":"https://openalex.org/licenses/publisher-specific-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},{"id":"doi:10.48550/arxiv.2601.19210","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2601.19210","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:doi:10.48550/arxiv.2601.19210","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"publisher-specific-oa","license_id":"https://openalex.org/licenses/publisher-specific-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Vision-language":[0],"models":[1],"(VLMs)":[2],"such":[3],"as":[4],"CLIP":[5],"have":[6],"demonstrated":[7],"remarkable":[8],"zero-shot":[9],"generalization,":[10],"yet":[11],"remain":[12],"highly":[13],"vulnerable":[14],"to":[15,27,74,99],"adversarial":[16],"examples":[17],"(AEs).":[18],"While":[19],"test-time":[20,87],"defenses":[21],"are":[22,35],"promising,":[23],"existing":[24],"methods":[25],"fail":[26],"provide":[28],"sufficient":[29],"robustness":[30],"against":[31,133],"strong":[32,134],"attacks":[33],"and":[34,42],"often":[36],"hampered":[37],"by":[38,51,128],"high":[39],"inference":[40,138],"latency":[41],"task-specific":[43],"applicability.":[44],"To":[45],"address":[46],"these":[47],"limitations,":[48],"we":[49,83],"start":[50],"investigating":[52],"the":[53,75,101,104,126],"intrinsic":[54],"properties":[55],"of":[56,131],"AEs,":[57],"which":[58,112],"reveals":[59],"that":[60,123],"AEs":[61],"exhibit":[62],"severe":[63],"feature":[64],"inconsistency":[65],"under":[66,107],"progressive":[67],"frequency":[68],"attenuation.":[69],"We":[70],"further":[71],"attribute":[72],"this":[73,81],"model's":[76],"inherent":[77],"spectral":[78],"bias.":[79],"Leveraging":[80],"insight,":[82],"propose":[84],"an":[85,129],"efficient":[86],"defense":[88],"named":[89],"Contrastive":[90],"Spectral":[91],"Rectification":[92],"(CSR).":[93],"CSR":[94,124,141],"optimizes":[95],"a":[96,108],"rectification":[97],"perturbation":[98],"realign":[100],"input":[102],"with":[103,136],"natural":[105],"manifold":[106],"spectral-guided":[109],"contrastive":[110],"objective,":[111],"is":[113,150],"applied":[114],"input-adaptively.":[115],"Extensive":[116],"experiments":[117],"across":[118,145],"16":[119],"classification":[120],"benchmarks":[121],"demonstrate":[122],"outperforms":[125],"SOTA":[127],"average":[130],"18.1%":[132],"AutoAttack":[135],"modest":[137],"overhead.":[139],"Furthermore,":[140],"exhibits":[142],"broad":[143],"applicability":[144],"diverse":[146],"visual":[147],"tasks.":[148],"Code":[149],"available":[151],"at":[152],"https://github.com/Summu77/CSR.":[153]},"counts_by_year":[],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2026-01-29T00:00:00"}
