Adversarial Examples in Multi-Layer Random ReLU Networks
Peter L. Bartlett, Sébastien Bubeck, Yeshwanth Cherapanamjeri
Abstract
We consider the phenomenon of adversarial examples in ReLU networks with independent gaussian parameters. For networks of constant depth and with a large range of widths (for instance, it suffices if the width of each layer is polynomial in that of any other layer), small perturbations of input vectors lead to large changes of outputs. This generalizes results of Daniely and Schacham (2020) for networks of rapidly decreasing width and of Bubeck et al ( 2021 ) for two-layer networks. The proof shows that adversarial examples arise in these networks because the functions that they compute are very close to linear. Bottleneck layers in the network play a key role: the minimal width up to some point in the network determines scales and sensitivities of mappings computed up to that point. The main result is for networks with constant depth, but we also show that some constraint on depth is necessary for a result of this kind, because there are suitably deep networks that, with constant probability, compute a function that is close to constant.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f6e1f116-bedf-45f7-abcd-353584a7d355Cited by top-tier papers15
- Cross-Entropy Loss Functions: Theoretical Analysis and ApplicationsAnqi Mao, Mehryar Mohri, Yutao ZhongICML 2023 · 790 citations
- H-Consistency Bounds for Surrogate Loss MinimizersPranjal Awasthi, Anqi Mao, Mehryar Mohri, Yutao ZhongICML 2022 · 50 citations
- Gradient Methods Provably Converge to Non-Robust NetworksGal Vardi, Gilad Yehudai, Ohad ShamirNeurIPS 2022 · 32 citations
- On the Existence of The Adversarial Bayes ClassifierPranjal Awasthi, Natalie Frank, Mehryar MohriNeurIPS 2021 · 29 citations
- The Double-Edged Sword of Implicit Bias: Generalization vs. Robustness in ReLU NetworksSpencer Frei, Gal Vardi, Peter L. Bartlett, Nati SrebroNeurIPS 2023 · 25 citations
Builds on1
Related papers
- Most ReLU Networks Suffer from Adversarial PerturbationsAmit Daniely, Hadas ShachamNeurIPS 2020 · 17 citations
- A single gradient step finds adversarial examples on random two-layers neural networksSébastien Bubeck, Yeshwanth Cherapanamjeri, Gauthier Gidel, Remi Tachet des CombesNeurIPS 2021 · 31 citations
- Adversarial Robustness Guarantees for Random Deep Neural NetworksGiacomo De Palma, Bobak Toussi Kiani, Seth LloydICML 2021 · 10 citations
- Functional vs. parametric equivalence of ReLU networksMary Phuong, Christoph H. LampertICLR 2020 · 53 citations
- Contrasting Adversarial Perturbations: The Space of Harmless PerturbationsLu Chen, Shaofeng Li, Benhao Huang, Fan Yang et al.AAAI 2025 · 1 citation
