Holistic Adversarially Robust Pruning
Qi Zhao, Christian Wressnegger
Abstract
Neural networks can be drastically shrunk in size by removing redundant parameters. While crucial for the deployment on resource-constraint hardware, oftentimes, compression comes with a severe drop in accuracy and lack of adversarial robustness. Despite recent advances, counteracting both aspects has only succeeded for moderate compression rates so far. We propose a novel method, HARP, that copes with aggressive pruning significantly better than prior work. For this, we consider the network holistically. We learn a global compression strategy that optimizes how many parameters (compression rate) and which parameters (scoring connections) to prune specific to each layer individually. Our method fine-tunes an existing model with dynamic regularization, that follows a step-wise incremental function balancing the different objectives. It starts by favoring robustness before shifting focus on reaching the target compression rate and only then handles the objectives equally. The learned compression strategies allow us to maintain the pre-trained model's natural accuracy and its adversarial robustness for a reduction by 99 % of the network's original size. Moreover, we observe a crucial influence of non-uniform compression across layers. The implementation of HARP is publicly available at https://intellisec.de/research/harp .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Adaptive Sharpness-Aware Pruning for Robust Sparse NetworksAnna Bair, Hongxu Yin, Maying Shen, Pavlo Molchanov et al.ICLR 2024 · 19 citations
- One Less Reason for Filter Pruning: Gaining Free Adversarial Robustness with Structured Grouped Kernel PruningShaochen (Henry) Zhong, Zaichuan You, Jiamu Zhang, Sebastian Zhao et al.NeurIPS 2023 · 13 citations
- BiPFT: Binary Pre-trained Foundation Transformer with Low-Rank Estimation of Binarization Residual PolynomialsXingrun Xing, Li Du, Xinyuan Wang, Xianlin Zeng et al.AAAI 2024 · 5 citations
- Two is Better than One: Efficient Ensemble Defense for Robust and Compact ModelsYoojin Jung, Byung Cheol SongCVPR 2025
- A Robust Optimization Guided Pruning Framework for Vision and Large Language ModelsGabriel Afriat, Hussein Hazimeh, Dimitris Paparas, Rahul MazumderICML 2026
Builds on14
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey et al.ICLR 2020 · 829 citations
- Rigging the Lottery: Making All Tickets WinnersUtku Evci, Trevor Gale, Jacob Menick, Pablo Samuel Castro et al.ICML 2020 · 723 citations
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
Related papers
- HYDRA: Pruning Adversarially Robust Neural NetworksVikash Sehwag, Shiqi Wang, Prateek Mittal, Suman JanaNeurIPS 2020 · 242 citations
- Dynamical Low-Rank Compression of Neural Networks with Robustness under Adversarial AttacksSteffen Schotthöfer, Lexie Yang, Stefan SchnakeNeurIPS 2025 · 9 citations
- Training Adversarially Robust Sparse Networks via Bayesian Connectivity SamplingOzan Özdenizci, Robert LegensteinICML 2021 · 31 citations
- DPFPS: Dynamic and Progressive Filter Pruning for Compressing Convolutional Neural Networks from ScratchXiaofeng Ruan, Yufan Liu, Bing Li, Chunfeng Yuan et al.AAAI 2021 · 49 citations
- OPQ: Compressing Deep Neural Networks with One-shot Pruning-QuantizationPeng Hu, Xi Peng, Hongyuan Zhu, Mohamed M. Sabry Aly et al.AAAI 2021 · 79 citations
