Figureure 2 · Overview of the proposed RITA frameworkFigure 2. Overview of the proposed RITA framework. Given an adversarial test image, RITA extracts multi-view visual features and class-specific textual prototypes using a frozen CLIP encoder. Both modalities are modeled as discrete distributions and aligned via entropy-regularized optimal transport. Low-entropy views are used to update a dynamic cache of reliable semantics.这张图概括 Robustifying Vision-Language Models via Test-Time 的整体方法流程。阅读时先看模块之间传递的训练信号,再看作者如何把目标拆成可优化的子问题。Figureure 1 · Augmented views retain more semantic cues under adversarial perturbatiFigure 1. Augmented views retain more semantic cues under adversarial perturbations, enabeling a cache for distribution alignment that improves adversarial performance. (a) Visualization of adversarially perturbed images, where each point represents an image and different colors denote ground-truth classes. (b) Visualization of multiple augmented views generated from the same adversarial image, colored by class label, where semantic structure partially re-emerges with improved class separability compared to (a). (c) Our method leverages the selected augmented views as a cache and aligns them with textual prompts. (d) Performance comparison across different VLM backbones, demonstrating improved robustness under adversarial attacks.这张图/表用于判断 Robustifying Vision-Language Models via Test-Time 的实验收益来自哪里。重点看替换、消融或跨模型设置下趋势是否一致,而不是只看单个最高分。