Architectural Adversarial Robustness: The Case for Deep Pursuit
George Cazenavette, Calvin Murdock, Simon Lucey
Abstract
Despite their unmatched performance, deep neural networks remain susceptible to targeted attacks by nearly imperceptible levels of adversarial noise. While the underlying cause of this sensitivity is not well understood, theoretical analyses can be simplified by reframing each layer of a feed-forward network as an approximate solution to a sparse coding problem. Iterative solutions using basis pursuit are theoretically more stable and have improved adversarial robustness. However, cascading layer-wise pursuit implementations suffer from error accumulation in deeper networks. In contrast, our new method of deep pursuit approximates the activations of all layers as a single global optimization problem, allowing us to consider deeper, realworld architectures with skip connections such as residual networks. Experimentally, our approach demonstrates improved robustness to adversarial noise.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 387dad12-d101-41e1-b092-d326e4332a2cCited by top-tier papers4
- Exploring Architectural Ingredients of Adversarially Robust Deep Neural NetworksHanxun Huang, Yisen Wang, Sarah M. Erfani, Quanquan Gu et al.NeurIPS 2021 · 124 citations
- Revisiting Sparse Convolutional Model for Visual RecognitionXili Dai, Mingyang Li, Pengyuan Zhai, Shengbang Tong et al.NeurIPS 2022 · 45 citations
- Learning Diverse-Structured Networks for Adversarial RobustnessXuefeng Du, Jingfeng Zhang, Bo Han, Tongliang Liu et al.ICML 2021 · 22 citations
- Revisiting Residual Networks for Adversarial RobustnessShihua Huang, Zhichao Lu, Kalyanmoy Deb, Vishnu Naresh BoddetiCVPR 2023
Builds on6
- Large-Scale Adversarial Training for Vision-and-Language Representation LearningZhe Gan, Yen-Chun Chen, Linjie Li, Chen Zhu et al.NeurIPS 2020 · 561 citations
- Adversarial Training is a Form of Data-dependent Operator Norm RegularizationKevin Roth, Yannic Kilcher, Thomas HofmannNeurIPS 2020 · 61 citations
- Adversarial Robustness of Supervised Sparse CodingJeremias Sulam, Ramchandran Muthukumar, Raman AroraNeurIPS 2020 · 27 citations
- Dataless Model Selection With the Deep Frame PotentialCalvin Murdock, Simon LuceyCVPR 2020
- When NAS Meets Robustness: In Search of Robust Architectures Against Adversarial AttacksMinghao Guo, Yuzhe Yang, Rui Xu, Ziwei Liu et al.CVPR 2020
Related papers
- Implicit Euler Skip Connections: Enhancing Adversarial Robustness via Numerical StabilityMingjie Li, Lingshen He, Zhouchen LinICML 2020 · 36 citations
- Training Adversarially Robust Sparse Networks via Bayesian Connectivity SamplingOzan Özdenizci, Robert LegensteinICML 2021 · 31 citations
- Towards the Training of Deeper Predictive Coding Neural NetworksChang Qi, Matteo Forasassi, Thomas Lukasiewicz, Tommaso SalvatoriICML 2026 · 6 citations
- Towards Achieving Adversarial Robustness by Enforcing Feature Consistency Across Bit PlanesSravanti Addepalli, Vivek B. S., Arya Baburaj, Gaurang Sriramanan et al.CVPR 2020
- Attacking Optical FlowAnurag Ranjan, Joel Janai, Andreas Geiger, Michael J. BlackICCV 2019 · 93 citations
