PAC-Bayesian Spectrally-Normalized Bounds for Adversarially Robust Generalization
Jiancong Xiao, Ruoyu Sun, Zhi-Quan Luo
Abstract
Deep neural networks (DNNs) are vulnerable to adversarial attacks. It is found empirically that adversarially robust generalization is crucial in establishing defense algorithms against adversarial attacks. Therefore, it is interesting to study the theoretical guarantee of robust generalization. This paper focuses on norm-based complexity, based on a PAC-Bayes approach (Neyshabur et al., 2017). The main challenge lies in extending the key ingredient, which is a weight perturbation bound in standard settings, to the robust settings. Existing attempts heavily rely on additional strong assumptions, leading to loose bounds. In this paper, we address this issue and provide a spectrally-normalized robust generalization bound for DNNs. Compared to existing bounds, our bound offers two significant advantages: Firstly, it does not depend on additional assumptions. Secondly, it is considerably tighter, aligning with the bounds of standard generalization. Therefore, our result provides a different perspective on understanding robust generalization: The mismatch terms between standard and robust generalization bounds shown in previous studies do not contribute to the poor robust generalization. Instead, these disparities solely due to mathematical issues. Finally, we extend the main result to adversarial robustness against general non- attacks and other neural network architectures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 55072e36-c4b1-4595-92d8-7e6b22c1c5eaCited by top-tier papers4
- Transformed Low-Rank Parameterization Can Help Robust Generalization for Tensor Neural NetworksAndong Wang, Chao Li, Mingyuan Bai, Zhong Jin et al.NeurIPS 2023 · 12 citations
- Uniformly Stable Algorithms for Adversarial Training and BeyondJiancong Xiao, Jiawei Zhang, Zhi-Quan Luo, Asuman E. OzdaglarICML 2024 · 2 citations
- Enhancing Robust Fairness via Confusional Spectral RegularizationGaojie Jin, Sihao Wu, Jiaxu Liu, Tianjin Huang et al.ICLR 2025
- Restoring Calibration for Aligned Large Language Models: A Calibration-Aware Fine-Tuning ApproachJiancong Xiao, Bojian Hou, Zhanliang Wang, Ruochen Jin et al.ICML 2025
Builds on10
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- On the Algorithmic Stability of Adversarial TrainingYue Xing, Qifan Song, Guang ChengNeurIPS 2021 · 74 citations
Related papers
- Robust Design of Deep Neural Networks Against Adversarial Attacks Based on Lyapunov TheoryArash Rahnama, André T. Nguyen, Edward RaffCVPR 2020
- SoK: Certified Robustness for Deep Neural NetworksLinyi Li, Tao Xie, Bo LiS&P 2023
- A PAC-Bayes Analysis of Adversarial RobustnessPaul Viallard, Guillaume Vidot, Amaury Habrard, Emilie MorvantNeurIPS 2021 · 21 citations
- Improved Sample Complexities for Deep Neural Networks and Robust Classification via an All-Layer MarginColin Wei, Tengyu MaICLR 2020 · 91 citations
- Adversarial Robustness Across Representation SpacesPranjal Awasthi, George Yu, Chun-Sung Ferng, Andrew Tomkins et al.CVPR 2021
