Improving Robust Generalization by Direct PAC-Bayesian Bound Minimization
Zifan Wang, Nan Ding, Tomer Levinboim, Xi Chen, Radu Soricut
Abstract
Recent research in robust optimization has shown an overfitting-like phenomenon in which models trained against adversarial attacks exhibit higher robustness on the training set compared to the test set. Although previous work provided theoretical explanations for this phenomenon using a robust PAC-Bayesian bound over the adversarial test error, related algorithmic derivations are at best only loosely connected to this bound, which implies that there is still a gap between their empirical success and our understanding of adversarial robustness theory. To close this gap, in this paper we consider a different form of the robust PAC-Bayesian bound and directly minimize it with respect to the model posterior. The derivation of the optimal solution connects PAC-Bayesian learning to the geometry of the robust loss surface through a Trace of Hessian (TrH) regularizer that measures the surface flatness. In practice, we restrict the TrH regularizer to the top layer only, which results in an analytical solution to the bound whose computational cost does not depend on the network depth. Finally, we evaluate our TrH regularization approach over CIFAR-10/100 and ImageNet using Vision Transformers (ViT) and compare against baseline adversarial robustness algorithms. Experimental results show that TrH regularization leads to improved ViT robustness that either matches or surpasses previous state-of-the-art approaches while at the same time requires less memory and computational cost.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Demystifying Structural Disparity in Graph Neural Networks: Can One Size Fit All?Haitao Mao, Zhikai Chen, Wei Jin, Haoyu Han et al.NeurIPS 2023 · 58 citations
- Variational Learning Finds Flatter Solutions at the Edge of StabilityAvrajit Ghosh, Bai Cong, Rio Yokota, Saiprasad Ravishankar et al.NeurIPS 2025 · 2 citations
- Efficient Source-Free Time-Series Adaptation via Parameter Subspace DisentanglementGaurav Patel, Christopher Michael Sandino, Behrooz Mahasseni, Ellen L. Zippi et al.ICLR 2025
- CGU-Bayes: Causal Graph Uncertainty-Guided Bayesian Inference for Domain GeneralizationNaiyu Yin, Hanjing Wang, Yue Yu, Tian Gao et al.CVPR 2026
Builds on22
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 35,902 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- CutMix: Regularization Strategy to Train Strong Classifiers With Localizable FeaturesSangdoo Yun, Dongyoon Han, Sanghyuk Chun, Seong Joon Oh et al.ICCV 2019 · 5,843 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
Related papers
- CR-SAM: Curvature Regularized Sharpness-Aware MinimizationTao Wu, Tie Luo, Donald C. Wunsch IIAAAI 2024 · 15 citations
- Benign Overfitting in Adversarial Training for Vision TransformersJiaming Zhang, Meng Ding, Shaopeng Fu, Jingfeng Zhang et al.ICML 2026 · 1 citation
- Relating Adversarially Robust Generalization to Flat MinimaDavid Stutz, Matthias Hein, Bernt SchieleICCV 2021 · 80 citations
- Towards Robust Vision Transformers: Path Dependency Analysis and a Simple Two-Stage Adversarial TrainingSeongmin Kim, Byung Cheol SongCVPR 2026
- A PAC-Bayes Analysis of Adversarial RobustnessPaul Viallard, Guillaume Vidot, Amaury Habrard, Emilie MorvantNeurIPS 2021 · 21 citations
