USENIX Security2026Top-tier venue
Sy-FAR: Symmetry-based Fair Adversarial Robustness
Haneen Najjar, Eyal Ronen, Mahmood Sharif
Abstract
Security-critical machine-learning (ML) systems, such as face-recognition systems, are susceptible to adversarial examples, including real-world physically realizable attacks. Various means to boost ML's adversarial robustness have been proposed; however, they typically induce unfair robustness: It is often easier to attack from certain classes (e.g., individuals) or groups (e.g., genders) than from others. Several techniques have been developed to improve adversarial robustness while seeking perfect fairness between classes. Yet, prior work has focused on settings where security and fairness are less critical (e.g., classifying objects such as cars and ships). Our insight is that achieving perfect parity in realistic fairness-critical tasks, such as face recognition, is often infeasible—some classes (e.g., siblings) may be highly similar, leading to more misclassifications between them. Instead, we suggest that seeking symmetry—i.e., attacks from class i to j would be as successful as from j to i—is more tractable. Intuitively, symmetry is desirable because class resemblance is a symmetric relation in most domains. Additionally, as we prove theoretically, symmetry between individuals induces symmetry between any set of sub-groups, in contrast to other fairness notions where group-fairness is often elusive. We develop Sy-FAR, a technique to encourage symmetry while also optimizing adversarial robustness and extensively evaluate it using five datasets, with three model architectures, including against targeted and untargeted realistic attacks. The results show Sy-FAR significantly improves fair adversarial robustness compared to state-of-the-art methods. Moreover, we find that Sy-FAR is faster and more consistent across runs. Notably, Sy-FAR also ameliorates another type of unfairness we discover in this work—target classes that adversarial examples are likely to be classified into become significantly less vulnerable after inducing symmetry.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d4d47b7c-2357-4533-b7ea-35e5633bdf24Builds on18
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face RecognitionMahmood Sharif, Sruti Bhagavatula, Lujo Bauer, Michael K. ReiterCCS 2016 · 1,765 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
Related papers
- On the Alignment between Fairness and Accuracy: from the Perspective of Adversarial RobustnessJunyi Chai, Taeuk Jang, Jing Gao, Xiaoqian WangICML 2025
- Towards Accuracy-Fairness Paradox: Adversarial Example-based Data Augmentation for Visual DebiasingYi Zhang, Jitao SangACM MM 2020 · 32 citations
- To be Robust or to be Fair: Towards Fairness in Adversarial TrainingHan Xu, Xiaorui Liu, Yaxin Li, Anil K. Jain et al.ICML 2021 · 218 citations
- Towards Interpreting and Utilizing Symmetry Property in Adversarial ExamplesShibin Mei, Chenglong Zhao, Bingbing Ni, Shengchao YuanAAAI 2023 · 3 citations
- Towards Fairness-Aware Adversarial LearningYanghao Zhang, Tianle Zhang, Ronghui Mu, Xiaowei Huang et al.CVPR 2024 · 6 citations
