Do Perceptually Aligned Gradients Imply Robustness?
Roy Ganz, Bahjat Kawar, Michael Elad
Abstract
Adversarially robust classifiers possess a trait that non-robust models do not -Perceptually Aligned Gradients (PAG). Their gradients with respect to the input align well with human perception. Several works have identified PAG as a byproduct of robust training, but none have considered it as a standalone phenomenon nor studied its own implications. In this work, we focus on this trait and test whether Perceptually Aligned Gradients imply Robustness. To this end, we develop a novel objective to directly promote PAG in training classifiers and examine whether models with such gradients are more robust to adversarial attacks. Extensive experiments on multiple datasets and architectures validate that models with aligned gradients exhibit significant robustness, exposing the surprising bidirectional connection between PAG and robustness. Lastly, we show that better gradient alignment leads to increased robustness and harness this observation to boost the robustness of existing adversarial training techniques. Our code is available at https: //github.com/royg27/PAG-ROB .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 7c93d573-6726-4aa1-a16c-d6222547d04eCited by top-tier papers7
- Adversarial Vulnerability from Interference Between Features in SuperpositionEdward Stevinson, Lucas Prieto, Melih Barsbey, Tolga BirdalICML 2026 · 4 citations
- Enhancing Consistency-Based Image Generation via Adversarialy-Trained Classification and Energy-Based DiscriminationShelly Golan, Roy Ganz, Michael EladNeurIPS 2024 · 3 citations
- Implicit Inversion turns CLIP into a DecoderAntonio D'Orazio, Maria Rosaria Briglia, Donato Crisostomi, Dario Loi et al.ICLR 2026 · 3 citations
- Counterfactual Explanations on Robust Perceptual GeodesicsEslam Zaher, Dr Maciej Trzaskowski, Quan Nguyen, Fred RoostaICLR 2026 · 2 citations
- Compressed Image Generation with Denoising Diffusion Codebook ModelsGuy Ohayon, Hila Manor, Tomer Michaeli, Michael EladICML 2025
Builds on24
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 13,211 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
Related papers
- Which Models have Perceptually-Aligned Gradients? An Explanation via Off-Manifold RobustnessSuraj Srinivas, Sebastian Bordt, Himabindu LakkarajuNeurIPS 2023 · 24 citations
- Balancing Generalization and Robustness in Adversarial Training via Steering through Clean and Adversarial Gradient DirectionsHaoyu Tong, Xiaoyu Zhang, Yulin Jin, Jian Lou et al.ACM MM 2024 · 2 citations
- Perceptual Adversarial Robustness: Defense Against Unseen Threat ModelsCassidy Laidlaw, Sahil Singla, Soheil FeiziICLR 2021 · 217 citations
- What It Thinks Is Important Is Important: Robustness Transfers Through Input GradientsAlvin Chan, Yi Tay, Yew-Soon OngCVPR 2020
- Failure Cases Are Better Learned but Boundary Says Sorry: Facilitating Smooth Perception Change for Accuracy-Robustness Trade-Off in Adversarial TrainingYanyun Wang, Li LiuICCV 2025 · 1 citation
