First Line of Defense: A Robust First Layer Mitigates Adversarial Attacks
Janani Suresh, Nancy Nayak, Sheetal Kalyani
Abstract
Adversarial training (AT) incurs significant computational overhead, leading to growing interest in designing inherently robust architectures. We demonstrate that a carefully designed first layer of the neural network can serve as an implicit adversarial noise filter (ANF). This filter is created using a combination of large kernel size, increased convolution filters, and a maxpool operation. We show that integrating this filter as the first layer in architectures such as ResNet, VGG, and EfficientNet results in adversarially robust networks. Our approach achieves higher adversarial accuracies than existing natively robust architectures without AT and is competitive with adversarial-trained architectures across a wide range of datasets. Supporting our findings, we show that (a) the decision regions for our method have better margins, (b) the visualized loss surfaces are smoother, (c) the modified peak signal-to-noise ratio (mPSNR) values at the output of the ANF are higher, (d) high-frequency components are more attenuated, and (e) architectures incorporating ANF exhibit better denoising in Gaussian noise compared to baseline architectures. Code for all our experiments are available at https://github.com/janani-suresh-97/first-line-defence.git .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e3a78fa3-514c-401c-b11e-9e112c2b7f95Cited by top-tier papers2
- DRIFT: Divergent Response in Filtered Transformations for Robust Adversarial DefenseAmira Guesmi, Muhammad ShafiqueICLR 2026 · 1 citation
- Towards Robust Vision Transformers: Path Dependency Analysis and a Simple Two-Stage Adversarial TrainingSeongmin Kim, Byung Cheol SongCVPR 2026
Builds on6
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
- Exploring Architectural Ingredients of Adversarially Robust Deep Neural NetworksHanxun Huang, Yisen Wang, Sarah M. Erfani, Quanquan Gu et al.NeurIPS 2021 · 124 citations
- CIFS: Improving Adversarial Robustness of CNNs via Channel-wise Importance-based Feature SelectionHanshu Yan, Jingfeng Zhang, Gang Niu, Jiashi Feng et al.ICML 2021 · 51 citations
- Adversarial Robustness through Random Weight SamplingYanxiang Ma, Minjing Dong, Chang XuNeurIPS 2023 · 22 citations
Related papers
- A Combination of Noise and Bilateral Filters Achieve Supralinear and Scalable Adversarial Robustness in CNNsNicolas Stalder, Benjamin F Grewe, Matteo Saponati, Pau Vilimelis AceitunoCVPR 2026
- AdvFilter: Predictive Perturbation-aware Filtering against Adversarial Attack via Multi-domain LearningYihao Huang, Qing Guo, Felix Juefei-Xu, Lei Ma et al.ACM MM 2021 · 13 citations
- Certify or Predict: Boosting Certified Robustness with Compositional ArchitecturesMark Niklas Müller, Mislav Balunovic, Martin T. VechevICLR 2021 · 14 citations
- Adversarial Training on Purification (AToP): Advancing Both Robustness and GeneralizationGuang Lin, Chao Li, Jianhai Zhang, Toshihisa Tanaka et al.ICLR 2024 · 25 citations
- Removing Adversarial Noise in Class Activation Feature SpaceDawei Zhou, Nannan Wang, Chunlei Peng, Xinbo Gao et al.ICCV 2021 · 37 citations
