Adversarial Reprogramming Revisited
Matthias Englert, Ranko Lazic
Abstract
Adversarial reprogramming, introduced by Elsayed, Goodfellow, and Sohl-Dickstein, seeks to repurpose a neural network to perform a different task, by manipulating its input without modifying its weights. We prove that two-layer ReLU neural networks with random weights can be adversarially reprogrammed to achieve arbitrarily high accuracy on Bernoulli data models over hypercube vertices, provided the network width is no greater than its input dimension. We also substantially strengthen a recent result of Phuong and Lampert on directional convergence of gradient flow, and obtain as a corollary that training two-layer ReLU neural networks on orthogonally separable datasets can cause their adversarial reprogramming to fail. We support these theoretical results by experiments that demonstrate that, as long as batch normalisation layers are suitably initialised, even untrained networks with random weights are susceptible to adversarial reprogramming. This is in contrast to observations in several recent works that suggested that adversarial reprogramming is not possible for untrained networks to any degree of reliability. * Equal contribution.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bfb13fca-7a50-4ffa-b949-4b902db13dffCited by top-tier papers5
- The Expressive Power of Low-Rank AdaptationYuchen Zeng, Kangwook LeeICLR 2024 · 116 citations
- Simplicity Bias of Two-Layer Networks beyond Linearly Separable DataNikita Tsoy, Nikola KonstantinovICML 2024 · 12 citations
- Lifting Manifolds to Mitigate Pseudo-Alignment in LLM4TSLiangwei Nathan Zheng, Wenhao Liang, Wei Emma Zhang, Miao Xu et al.WWW 2026 · 2 citations
- The impact of allocation strategies in subset learning on the expressive power of neural networksOfir Schlisselberg, Ran DarshanICLR 2025
- Deep Graph ReprogrammingYongcheng Jing, Chongbin Yuan, Li Ju, Yiding Yang et al.CVPR 2023
Builds on13
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Gradient Descent Maximizes the Margin of Homogeneous Neural NetworksKaifeng Lyu, Jian LiICLR 2020 · 402 citations
- Directional convergence and alignment in deep learningZiwei Ji, Matus TelgarskyNeurIPS 2020 · 226 citations
- Voice2Series: Reprogramming Acoustic Models for Time Series ClassificationChao-Han Huck Yang, Yun-Yun Tsai, Pin-Yu ChenICML 2021 · 150 citations
Related papers
- Adversarial Examples in Multi-Layer Random ReLU NetworksPeter L. Bartlett, Sébastien Bubeck, Yeshwanth CherapanamjeriNeurIPS 2021 · 33 citations
- Optimization Theory for ReLU Neural Networks Trained with Normalization LayersYonatan Dukler, Quanquan Gu, Guido MontúfarICML 2020 · 30 citations
- The inductive bias of ReLU networks on orthogonally separable dataMary Phuong, Christoph H. LampertICLR 2021 · 53 citations
- Training invariances and the low-rank phenomenon: beyond linear networksThien Le, Stefanie JegelkaICLR 2022 · 39 citations
- Can Implicit Bias Imply Adversarial Robustness?Hancheng Min, René VidalICML 2024 · 7 citations
