Computational Asymmetries in Robust Classification
Samuele Marro, Michele Lombardi
Abstract
In the context of adversarial robustness, we make three strongly related contributions. First, we prove that while attacking ReLU classifiers is -hard, ensuring their robustness at training time is -hard (even on a single example). This asymmetry provides a rationale for the fact that robust classifications approaches are frequently fooled in the literature. Second, we show that inference-time robustness certificates are not affected by this asymmetry, by introducing a proof-of-concept approach named Counter-Attack (CA). Indeed, CA displays a reversed asymmetry: running the defense is -hard, while attacking it is -hard. Finally, motivated by our previous result, we argue that adversarial attacks can be used in the context of robustness certification, and provide an empirical evaluation of their effectiveness. As a byproduct of this process, we also release UG100, a benchmark dataset for adversarial attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f6d21f50-176e-41f3-8d31-1f010e61d43fCited by top-tier papers1
Ask how each one uses itBuilds on5
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- MagNet: A Two-Pronged Defense against Adversarial ExamplesDongyu Meng, Hao ChenCCS 2017 · 1,295 citations
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov et al.S&P 2018 · 987 citations
- Evaluating the Adversarial Robustness of Adaptive Test-time DefensesFrancesco Croce, Sven Gowal, Thomas Brunner, Evan Shelhamer et al.ICML 2022 · 85 citations
Related papers
- Breaking Certified Defenses: Semantic Adversarial Examples with Spoofed robustness CertificatesAmin Ghiasi, Ali Shafahi, Tom GoldsteinICLR 2020 · 57 citations
- On the Vulnerability of Adversarially Trained Models Against Two-faced AttacksShengjie Zhou, Lue Tao, Yuzhou Cao, Tao Xiang et al.ICLR 2024
- Towards Robustness Certification Against Universal PerturbationsYi Zeng, Zhouxing Shi, Ming Jin, Feiyang Kang et al.ICLR 2023
- Gradient Flow Provably Learns Robust Classifiers for Orthonormal GMMsHancheng Min, René VidalICML 2025
- Provable robustness against all adversarial -perturbations for Francesco Croce, Matthias HeinICLR 2020 · 78 citations
