Improving Adversarial Robustness via Probabilistically Compact Loss with Logit Constraints
Xin Li, Xiangrui Li, Deng Pan, Dongxiao Zhu
Abstract
Convolutional neural networks (CNNs) have achieved stateof-the-art performance on various tasks in computer vision. However, recent studies demonstrate that these models are vulnerable to carefully crafted adversarial samples and suffer from a significant performance drop when predicting them. Many methods have been proposed to improve adversarial robustness (e.g., adversarial training and new loss functions to learn adversarially robust feature representations). Here we offer a unique insight into the predictive behavior of CNNs that they tend to misclassify adversarial samples into the most probable false classes. This inspires us to propose a new Probabilistically Compact (PC) loss with logit constraints which can be used as a drop-in replacement for cross-entropy (CE) loss to improve CNN's adversarial robustness. Specifically, PC loss enlarges the probability gaps between true class and false classes meanwhile the logit constraints prevent the gaps from being melted by a small perturbation. We extensively compare our method with the state-of-the-art using large scale datasets under both white-box and black-box attacks to demonstrate its effectiveness. The source codes are available from the following url: https://github.com/xinli0928/PC-LC .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d55b1329-7bce-4aeb-a70a-55fa6960d967Cited by top-tier papers2
- Learning Compact Features via In-Training Representation AlignmentXin Li, Xiangrui Li, Deng Pan, Yao Qiang et al.AAAI 2023 · 3 citations
- TIMA: Text-Image Mutual Awareness for Balancing Zero-Shot Adversarial Robustness and Generalization AbilityFengji Ma, Hei Victor Cheng, Chenxing Li, Li LiuAAAI 2026
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 1,295 citations
- Rethinking Softmax Cross-Entropy Loss for Adversarial RobustnessTianyu Pang, Kun Xu, Yinpeng Dong, Chao Du et al.ICLR 2020 · 176 citations
- Adversarial Defense by Restricting the Hidden Space of Deep Neural NetworksAamir Mustafa, Salman H. Khan, Munawar Hayat, Roland Goecke et al.ICCV 2019 · 160 citations
- Improving Adversarial Robustness via Guided Complement EntropyHao-Yun Chen, Jhao-Hong Liang, Shih-Chieh Chang, Jia-Yu Pan et al.ICCV 2019 · 51 citations
Related papers
- Understanding and Improving Adversarial Robustness of Neural Probabilistic CircuitsWeixin Chen, Han ZhaoNeurIPS 2025 · 1 citation
- Adversarial Neural Pruning with Latent Vulnerability SuppressionDivyam Madaan, Jinwoo Shin, Sung Ju HwangICML 2020 · 68 citations
- Cross-Entropy Loss Functions: Theoretical Analysis and ApplicationsAnqi Mao, Mehryar Mohri, Yutao ZhongICML 2023 · 790 citations
- Probabilistically Robust Learning: Balancing Average and Worst-case PerformanceAlexander Robey, Luiz F. O. Chamon, George J. Pappas, Hamed HassaniICML 2022 · 50 citations
- Calibrating Deep Neural Networks by Pairwise ConstraintsJiacheng Cheng, Nuno VasconcelosCVPR 2022 · 21 citations
