CSTAR: Towards Compact and Structured Deep Neural Networks with Adversarial Robustness
Huy Phan, Miao Yin, Yang Sui, Bo Yuan, Saman A. Zonouz
Abstract
Model compression and model defense for deep neural networks (DNNs) have been extensively and individually studied. Considering the co-importance of model compactness and robustness in practical applications, several prior works have explored to improve the adversarial robustness of the sparse neural networks. However, the structured sparse models obtained by the existing works suffer severe performance degradation for both benign and robust accuracy, thereby causing a challenging dilemma between robustness and structuredness of compact DNNs. To address this problem, in this paper, we propose CSTAR, an efficient solution that simultaneously impose Compactness, high STructuredness and high Adversarial Robustness on the target DNN models. By formulating the structuredness and robustness requirement within the same framework, the compressed DNNs can simultaneously achieve high compression performance and strong adversarial robustness. Evaluations for various DNN models on different datasets demonstrate the effectiveness of CSTAR. Compared with the state-of-the-art robust structured pruning, CSTAR shows consistently better performance. For instance, when compressing ResNet-18 on CIFAR-10, CSTAR achieves up to 20.07% and 11.91% improvement for benign accuracy and robust accuracy, respectively. For compressing ResNet-18 with 16x compression ratio on Imagenet, CSTAR obtains 8.58% benign accuracy gain and 4.27% robust accuracy gain compared to the existing robust structured pruning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 74b2ceaf-8d4e-4eb6-9db3-f6985d6e7404Cited by top-tier papers2
- TileMask: A Passive-Reflection-based Attack against mmWave Radar Object Detection in Autonomous DrivingYi Zhu, Chenglin Miao, Hongfei Xue, Zhengxiong Li et al.CCS 2023 · 16 citations
- Taxonomy Driven Fast Adversarial TrainingKun Tong, Chengze Jiang, Jie Gui, Yuan CaoAAAI 2024 · 2 citations
Builds on14
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey et al.ICLR 2020 · 829 citations
- HYDRA: Pruning Adversarially Robust Neural NetworksVikash Sehwag, Shiqi Wang, Prateek Mittal, Suman JanaNeurIPS 2020 · 242 citations
- CHIP: CHannel Independence-based Pruning for Compact Neural NetworksYang Sui, Miao Yin, Yi Xie, Huy Phan et al.NeurIPS 2021 · 198 citations
- Adversarial Robustness vs. Model Compression, or Both?Shaokai Ye, Xue Lin, Kaidi Xu, Sijia Liu et al.ICCV 2019 · 180 citations
Related papers
- Learning Adversarially Robust Sparse Networks via Weight ReparameterizationChenhao Li, Qiang Qiu, Zhibin Zhang, Jiafeng Guo et al.AAAI 2023 · 8 citations
- Two is Better than One: Efficient Ensemble Defense for Robust and Compact ModelsYoojin Jung, Byung Cheol SongCVPR 2025
- Adaptive Sharpness-Aware Pruning for Robust Sparse NetworksAnna Bair, Hongxu Yin, Maying Shen, Pavlo Molchanov et al.ICLR 2024 · 19 citations
- On the Interaction of Compressibility and Adversarial RobustnessMelih Barsbey, Antônio H. Ribeiro, Umut Simsekli, Tolga BirdalICLR 2026 · 3 citations
- Certify or Predict: Boosting Certified Robustness with Compositional ArchitecturesMark Niklas Müller, Mislav Balunovic, Martin T. VechevICLR 2021 · 14 citations
