paper-with-me

홈 › Papers

On the Interaction of Compressibility and Adversarial Robustness

2025-07-23 · Melih Barsbey, Antônio H. Ribeiro, Umut Şimşekli, Tolga Birdal arxiv

Modern neural networks are expected to simultaneously satisfy a host of desirable properties: accurate fitting to training data, generalization to unseen inputs, parameter and computational efficiency, and robustness to adversarial perturbations. While compressibility and robustness have each been studied extensively, a unified understanding of their interaction still remains elusive. In this work, we develop a principled framework to analyze how different forms of compressibility - such as neuron-level sparsity and spectral compressibility - affect adversarial robustness. We show that these forms of compression can induce a small number of highly sensitive directions in the representation space, which adversaries can exploit to construct effective perturbations. Our analysis yields a simple yet instructive robustness bound, revealing how neuron and spectral compressibility impact $L_\infty$ and $L_2$ robustness via their effects on the learned representations. Crucially, the vulnerabilities we identify arise irrespective of how compression is achieved - whether via regularization, architectural bias, or implicit learning dynamics. Through empirical evaluations across synthetic and realistic tasks, we confirm our theoretical predictions, and further demonstrate that these vulnerabilities persist under adversarial training and transfer learning, and contribute to the emergence of universal adversarial perturbations. Our findings show a fundamental tension between structured compressibility and robustness, and suggest new pathways for designing models that are both efficient and secure.

📄 PDF Abstract BibTeX arXiv:2507.17725

Code (0)

등록된 구현이 없습니다.

Tasks

Computational EfficiencyAdversarial RobustnessTransfer Learning

Similar Papers 제목 키워드 기반

Towards a Unified Game-Theoretic View of Adversarial Perturbations and Robustness

2021-12-01 · NeurIPS 2021 12 · Jie Ren, Die Zhang, Yisen Wang, Lu Chen 외

This paper provides a unified view to explain different adversarial attacks and defense methods, i.e. the view of multi-order interactions between input variables of DNNs. Based on the multi-order interaction, we discove…

Adversarial Robustness

A Unified Game-Theoretic Interpretation of Adversarial Robustness

2021-03-12 · Jie Ren, Die Zhang, Yisen Wang, Lu Chen 외

This paper provides a unified view to explain different adversarial attacks and defense methods, i.e. the view of multi-order interactions between input variables of DNNs. Based on the multi-order interaction, we discove…

Adversarial Robustness

A Unified Game-Theoretic Interpretation of Adversarial Robustness

2021-11-05 · Jie Ren, Die Zhang, Yisen Wang, Lu Chen 외

This paper provides a unified view to explain different adversarial attacks and defense methods, \emph{i.e.} the view of multi-order interactions between input variables of DNNs. Based on the multi-order interaction, we …

Adversarial Robustness

Large Learning Rates Simultaneously Achieve Robustness to Spurious Correlations and Compressibility

2025-07-23 · Melih Barsbey, Lucas Prieto, Stefanos Zafeiriou, Tolga Birdal arxiv

Robustness and resource-efficiency are two highly desirable properties for modern machine learning models. However, achieving them jointly remains a challenge. In this paper, we identify high learning rates as a facilita…

Balancing Robustness and Efficiency in Embedded DNNs Through Activation Function Selection

2025-04-07 · Jon Gutiérrez Zaballa, Koldo Basterretxea, Javier Echanobe

Machine learning-based embedded systems for safety-critical applications, such as aerospace and autonomous driving, must be robust to perturbations caused by soft errors. As transistor geometries shrink and voltages decr…

Autonomous DrivingDecoderQuantizationSemantic Segmentation