Gradient Flow Provably Learns Robust Classifiers for Orthonormal GMMs
Hancheng Min, René Vidal
Abstract
Deep learning-based classifiers are known to be vulnerable to adversarial attacks. Existing methods for defending against such attacks require adding a defense mechanism or modifying the learning procedure (e.g., by adding adversarial examples). This paper shows that for certain data distributions one can learn a provably robust classifier using standard learning methods and without adding a defense mechanism. More specifically, this paper addresses the problem of finding a robust classifier for a binary classification problem in which the data comes from an isotropic mixture of Gaussians with orthonormal cluster centers. First, we characterize the largest ℓ 2 -attack any classifier can defend against while maintaining high accuracy, and show the existence of optimal robust classifiers achieving this maximum ℓ 2 -robustness. Next, we show that given data from the orthonormal Gaussian mixture model, gradient flow on a two-layer network with a polynomial ReLU activation and without adversarial examples provably finds an optimal robust classifier.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 274d9cb4-9f67-4908-b5c7-a86c4a667364Cited by top-tier papers3
- A Provable Energy-Guided Test-Time Defense Boosting Adversarial Robustness of Large Vision-Language ModelsMujtaba Hussain Mirza, Antonio D’Orazio, Odelia Melamed, Iacopo MasiCVPR 2026 · 2 citations
- Transformers Learn the Optimal DDPM Denoiser for Multi-Token GMMsHongkang Li, Hancheng Min, Rene VidalICML 2026 · 1 citation
- The Implicit Bias of Adam and Muon on Smooth Homogeneous Neural NetworksEitan Gronich, Gal VardiICML 2026
Builds on13
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- (De)Randomized Smoothing for Certifiable Defense against Patch AttacksAlexander Levine, Soheil FeiziNeurIPS 2020 · 188 citations
- Small random initialization is akin to spectral learning: Optimization and generalization guarantees for overparameterized low-rank matrix reconstructionDominik Stöger, Mahdi SoltanolkotabiNeurIPS 2021 · 101 citations
- Gradient flow dynamics of shallow ReLU networks for square loss and orthogonal inputsEtienne Boursier, Loucas Pillaud-Vivien, Nicolas FlammarionNeurIPS 2022 · 92 citations
Related papers
- Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial RobustnessAmbar Pal, Jeremias Sulam, René VidalNeurIPS 2023 · 15 citations
- AdvFlow: Inconspicuous Black-box Adversarial Attacks using Normalizing FlowsHadi Mohaghegh Dolatabadi, Sarah M. Erfani, Christopher LeckieNeurIPS 2020 · 75 citations
- Regularized Training and Tight Certification for Randomized Smoothed Classifier with Provable RobustnessHuijie Feng, Chunpeng Wu, Guoyang Chen, Weifeng Zhang et al.AAAI 2020 · 13 citations
- MACER: Attack-free and Scalable Robust Training via Maximizing Certified RadiusRuntian Zhai, Chen Dan, Di He, Huan Zhang et al.ICLR 2020 · 195 citations
- Gradient Methods Provably Converge to Non-Robust NetworksGal Vardi, Gilad Yehudai, Ohad ShamirNeurIPS 2022 · 32 citations
