Feature Collapse Under Corruption: An Entropy Perspective on Robust Neural Networks
Vishesh Kumar, Akshay Agarwal
Abstract
Even after decades of advances in neural network training, the inherent robustness challenge remains open. While the sensitivity to adversarial perturbations is understandable given their intentional learning, the most surprising fact is the vulnerability to natural corruptions. Surprisingly, not only is the cause of this inherent vulnerability unknown, but the concern extends beyond traditional CNNs; it also applies to current models, including transformers and large foundation models. For the first time, through this work, we observe that natural corruptions often collapse the network's internal feature space into a high-entropy state, causing predictions to rely on a small subset of fragile features. Inspired by this, we propose a simple yet effective entropy-guided fine-tuning framework, Dem-HEC, that strengthens corruption robustness while maintaining clean accuracy. Our method generates high-entropy samples within a bounded perturbation region and repairs the model using both clean and high-entropy samples. We further combine this objective with distilling knowledge from a teacher snapshot to maintain stable predictions. The proposed Dem-HEC is effective across datasets ranging from small to large-resolution, from pure CNNs to transformers, and to large foundation models, including DinoV3. The proposed approach outperforms the state-of-the-art (SOTA) models not only in improving robustness but also in retaining or boosting clean accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e6550bbc-d18e-4af9-89b5-72618a88e95aBuilds on7
- TrivialAugment: Tuning-free Yet State-of-the-Art Data AugmentationSamuel G. Müller, Frank HutterICCV 2021 · 384 citations
- AugMax: Adversarial Composition of Random Augmentations for Robust TrainingHaotao Wang, Chaowei Xiao, Jean Kossaifi, Zhiding Yu et al.NeurIPS 2021 · 153 citations
- Measuring Robustness in Deep Learning Based Compressive SensingMohammad Zalbagi Darestani, Akshay S. Chaudhari, Reinhard HeckelICML 2021 · 94 citations
- IPMix: Label-Preserving Data Augmentation Method for Training Robust ClassifiersZhenglin Huang, Xiaoan Bao, Na Zhang, Qingqi Zhang et al.NeurIPS 2023 · 26 citations
- Democratic Training Against Universal Adversarial PerturbationsBing Sun, Jun Sun, Wei ZhaoICLR 2025
Related papers
- Improving Robustness of Vision Transformers by Reducing Sensitivity to Patch CorruptionsYong Guo, David Stutz, Bernt SchieleCVPR 2023
- Maximum-Entropy Adversarial Data Augmentation for Improved Generalization and RobustnessLong Zhao, Ting Liu, Xi Peng, Dimitris N. MetaxasNeurIPS 2020 · 207 citations
- MetaRepair: Learning to Repair Deep Neural Networks from Repairing ExperiencesYun Xing, Qing Guo, Xiaofeng Cao, Ivor W. Tsang et al.ACM MM 2024 · 5 citations
- Revisiting Unnaturalness for Automated Program Repair in the Era of Large Language ModelsAidan Z. H. Yang, Sophia Kolak, Vincent J. Hellendoorn, Ruben Martins et al.ICSE 2025 · 2 citations
- Mitigating Feature Gap for Adversarial Robustness by Feature DisentanglementNuoyan Zhou, Dawei Zhou, Decheng Liu, Nannan Wang et al.AAAI 2025 · 3 citations
