Generalized but not Robust? Comparing the Effects of Data Modification Methods on Out-of-Domain Generalization and Adversarial Robustness

Data modification, either via additional training datasets, data\naugmentation, debiasing, and dataset filtering, has been proposed as an\neffective solution for generalizing to out-of-domain (OOD) inputs, in both\nnatural language processing and computer vision literature. However, the effect\nof data modification on adversarial robustness remains unclear. In this work,\nwe conduct a comprehensive study of common data modification strategies and\nevaluate not only their in-domain and OOD performance, but also their\nadversarial robustness (AR). We also present results on a two-dimensional\nsynthetic dataset to visualize the effect of each method on the training\ndistribution. This work serves as an empirical study towards understanding the\nrelationship between generalizing to unseen domains and defending against\nadversarial perturbations. Our findings suggest that more data (either via\nadditional datasets or data augmentation) benefits both OOD accuracy and AR.\nHowever, data filtering (previously shown to improve OOD accuracy on natural\nlanguage inference) hurts OOD accuracy on other tasks such as question\nanswering and image classification. We provide insights from our experiments to\ninform future work in this direction.\n

Paper

References (82)

Scroll for more · 38 remaining

Similar papers

© 2026 NYSGPT2525 LLC