On the Interaction of Compressibility and Adversarial Robustness
Melih Barsbey, Antônio H. Ribeiro, Umut Simsekli, Tolga Birdal
Abstract
Modern neural networks are expected to simultaneously satisfy a host of desirable properties: accurate fitting to training data, generalization to unseen inputs, parameter and computational efficiency, and robustness to adversarial perturbations. While compressibility and robustness have each been studied extensively, a unified understanding of their interaction still remains elusive. In this work, we develop a principled framework to analyze how different forms of compressibility -such as neuron-level sparsity and spectral compressibilityaffect adversarial robustness. We show that these forms of compression can induce a small number of highly sensitive directions in the representation space, which adversaries can exploit to construct effective perturbations. Our analysis yields a simple yet instructive robustness bound, revealing how neuron and spectral compressibility impact ℓ ∞ and ℓ 2 robustness via their effects on the learned representations. Crucially, the vulnerabilities we identify arise irrespective of how compression is achieved -whether via regularization, architectural bias, or implicit learning dynamics. Through empirical evaluations across synthetic and realistic tasks, we confirm our theoretical predictions, and further demonstrate that these vulnerabilities persist under adversarial training and transfer learning, and contribute to the emergence of universal adversarial perturbations. Our findings show a fundamental tension between structured compressibility and robustness and highlight new pathways for designing models that are both efficient and safe.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5b355507-15de-4331-86a0-4fca246e9c8dCited by top-tier papers1
Ask how each one uses itBuilds on22
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu et al.ICCV 2021 · 31,683 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Layer-adaptive Sparsity for the Magnitude-based PruningJaeho Lee, Sejun Park, Sangwoo Mo, Sungsoo Ahn et al.ICLR 2021 · 331 citations
Related papers
- Dynamical Low-Rank Compression of Neural Networks with Robustness under Adversarial AttacksSteffen Schotthöfer, Lexie Yang, Stefan SchnakeNeurIPS 2025 · 9 citations
- Large Learning Rates Simultaneously Achieve Robustness to Spurious Correlations and CompressibilityMelih Barsbey, Lucas Prieto, Stefanos Zafeiriou, Tolga BirdalICCV 2025 · 3 citations
- CSTAR: Towards Compact and Structured Deep Neural Networks with Adversarial RobustnessHuy Phan, Miao Yin, Yang Sui, Bo Yuan et al.AAAI 2023 · 10 citations
- Adversarial Robustness vs. Model Compression, or Both?Shaokai Ye, Xue Lin, Kaidi Xu, Sijia Liu et al.ICCV 2019 · 180 citations
- How Many Perturbations Break This Model? Evaluating Robustness Beyond Adversarial AccuracyRaphaël Olivier, Bhiksha RajICML 2023 · 11 citations
