Large Norms of CNN Layers Do Not Hurt Adversarial Robustness
Youwei Liang, Dong Huang
Abstract
Since the Lipschitz properties of convolutional neural networks (CNNs) are widely considered to be related to adversarial robustness, we theoretically characterize the L-1 norm and L-infinity norm of 2D multi-channel convolutional layers and provide efficient methods to compute the exact L-1 norm and L-infinity norm. Based on our theorem, we propose a novel regularization method termed norm decay, which can effectively reduce the norms of convolutional layers and fully-connected layers. Experiments show that norm-regularization methods, including norm decay, weight decay, and singular value clipping, can improve generalization of CNNs. However, they can slightly hurt adversarial robustness. Observing this unexpected phenomenon, we compute the norms of layers in the CNNs trained with three different adversarial training frameworks and surprisingly find that adversarially robust CNNs have comparable or even larger layer norms than their non-adversarially robust counterparts. Furthermore, we prove that under a mild assumption, adversarially robust classifiers can be achieved using neural networks, and an adversarially robust neural network can have an arbitrarily large Lipschitz constant. For this reason, enforcing small norms on CNN layers may be neither necessary nor effective in achieving adversarial robustness. The code is available at https://github.com/youweiliang/norm_robustness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0b53d980-c545-4492-9796-2c1c24792b92Cited by top-tier papers3
- Fantastic Robustness Measures: The Secrets of Robust GeneralizationHoki Kim, Jinseong Park, Yujin Choi, Jaewook LeeNeurIPS 2023 · 13 citations
- When Flatness Does (Not) Guarantee Adversarial RobustnessNils Philipp Walter, Linara Adilova, Jilles Vreeken, Michael KampICLR 2026 · 7 citations
- A Black-Box Evaluation Framework for Semantic Robustness in Bird's Eye View DetectionFu Wang, Yanghao Zhang, Xiangyu Yin, Guangliang Cheng et al.AAAI 2025 · 1 citation
Builds on5
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey et al.ICLR 2020 · 829 citations
- A Closer Look at Accuracy vs. RobustnessYao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov et al.NeurIPS 2020 · 336 citations
- Boosting Adversarial Training with Hypersphere EmbeddingTianyu Pang, Xiao Yang, Yinpeng Dong, Taufik Xu et al.NeurIPS 2020 · 170 citations
- Designing Network Design SpacesIlija Radosavovic, Raj Prateek Kosaraju, Ross B. Girshick, Kaiming He et al.CVPR 2020
Related papers
- Improved techniques for deterministic l2 robustnessSahil Singla, Soheil FeiziNeurIPS 2022 · 13 citations
- On Lipschitz Regularization of Convolutional Layers using Toeplitz Matrix TheoryAlexandre Araujo, Benjamin Négrevergne, Yann Chevaleyre, Jamal AtifAAAI 2021 · 31 citations
- Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100Sahil Singla, Surbhi Singla, Soheil FeiziICLR 2022 · 77 citations
- Defending against Universal Adversarial Patches by Clipping Feature NormsCheng Yu, Jiansheng Chen, Youze Xue, Yuyang Liu et al.ICCV 2021 · 34 citations
- Skew Orthogonal ConvolutionsSahil Singla, Soheil FeiziICML 2021 · 76 citations
