SPADE: A Spectral Method for Black-Box Adversarial Robustness Evaluation
Wuxinlin Cheng, Chenhui Deng, Zhiqiang Zhao, Yaohui Cai, Zhiru Zhang, Zhuo Feng
Abstract
A black-box spectral method is introduced for evaluating the adversarial robustness of a given machine learning (ML) model. Our approach, named SPADE, exploits bijective distance mapping between the input/output graphs constructed for approximating the manifolds corresponding to the input/output data. By leveraging the generalized Courant-Fischer theorem, we propose a SPADE score for evaluating the adversarial robustness of a given model, which is proved to be an upper bound of the best Lipschitz constant under the manifold setting. To reveal the most non-robust data samples highly vulnerable to adversarial attacks, we develop a spectral graph embedding procedure leveraging dominant generalized eigenvectors. This embedding step allows assigning each data sample a robustness score that can be further harnessed for more effective adversarial training. Our experiments show the proposed SPADE method leads to promising empirical results for neural network models that are adversarially trained with the MNIST and CIFAR-10 data sets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d91c946a-65cd-4a51-a3ea-c8714b91b242Cited by top-tier papers3
- Bounding the Expected Robustness of Graph Neural Networks Subject to Node Feature AttacksYassine Abbahaddou, Sofiane Ennadir, Johannes F. Lutzeyer, Michalis Vazirgiannis et al.ICLR 2024 · 15 citations
- SGM-PINN: Sampling Graphical Models for Faster Training of Physics-Informed Neural NetworksJohn Anticev, Ali Aghdaei, Wuxinlin Cheng, Zhuo FengDAC 2024 · 1 citation
- CirSTAG: Circuit Stability Analysis on Graph-based ManifoldsWuxinlin Cheng, Yihang Yuan, Chenhui Deng, Ali Aghdaei et al.DAC 2025 · 1 citation
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph et al.ICLR 2020 · 1,572 citations
- Graph Structure Learning for Robust Graph Neural NetworksWei Jin, Yao Ma, Xiaorui Liu, Xianfeng Tang et al.KDD 2020 · 604 citations
- ML-LOO: Detecting Adversarial Examples with Feature AttributionPuyudi Yang, Jianbo Chen, Cho-Jui Hsieh, Jane-Ling Wang et al.AAAI 2020 · 117 citations
Related papers
- Lipschitz Bounds and Provably Robust Training by Laplacian SmoothingVishaal Krishnan, Abed AlRahman Al Makdah, Fabio PasqualettiNeurIPS 2020 · 28 citations
- Graph Structural Attack by Perturbing Spectral DistanceLu Lin, Ethan Blaser, Hongning WangKDD 2022 · 28 citations
- Certified Robustness via Dynamic Margin Maximization and Improved Lipschitz RegularizationMahyar Fazlyab, Taha Entesari, Aniket Roy, Rama ChellappaNeurIPS 2023 · 26 citations
- Not All Low-Pass Filters are Robust in Graph Convolutional NetworksHeng Chang, Yu Rong, Tingyang Xu, Yatao Bian et al.NeurIPS 2021 · 65 citations
- Provably Safeguarding a Classifier from OOD and Adversarial SamplesNicolas Atienza, Johanne Cohen, Christophe Labreuche, Michèle SebagICLR 2025
