Fundamental limits on the robustness of image classifiers
Zheng Dai, David Gifford
2023Year
Abstract
We prove that image classifiers are fundamentally sensitive to small perturbations in their inputs. Specifically, we show that given some image space of -by- images, all but a tiny fraction of images in any image class induced over that space can be moved outside that class by adding some perturbation whose -norm is , as long as that image class takes up at most half of the image space. We then show that is asymptotically optimal. Finally, we show that an increase in the bit depth of the image space leads to a loss in robustness. We supplement our results with a discussion of their implications for vision systems.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- Feature compression is the root cause of adversarial fragility in neural networksJingchao Gao, Ziqing Lu, Raghu Mudumbai, Xiaodong Wu et al.ICLR 2026 · 3 citations
- Why adversarial training can hurt robust accuracyJacob Clarysse, Julia Hörrmann, Fanny YangICLR 2023 · 6 citations
- Adaptive Image Anonymization in the Context of Image Classification with Neural NetworksNadiya Shvai, Arcadi Llanza Carmona, Amir NakibICCV 2023 · 6 citations
- Defending Against Universal Perturbations With Shared Adversarial TrainingChaithanya Kumar Mummadi, Thomas Brox, Jan Hendrik MetzenICCV 2019 · 61 citations
- Adversarial Robustness Limits via Scaling-Law and Human-Alignment StudiesBrian R. Bartoldson, James Diffenderfer, Konstantinos Parasyris, Bhavya KailkhuraICML 2024 · 45 citations
