Adversarial Robustness is at Odds with Lazy Training
Yunjuan Wang, Enayat Ullah, Poorya Mianjy, Raman Arora
Abstract
Recent works show that adversarial examples exist for random neural networks [Daniely and Shacham, 2020] and that these examples can be found using a single step of gradient ascent [Bubeck et al., 2021] . In this work, we extend this line of work to "lazy training" of neural networks -a dominant model in deep learning theory in which neural networks are provably efficiently learnable. We show that over-parametrized neural networks that are guaranteed to generalize well and enjoy strong computational guarantees remain vulnerable to attacks generated using a single step of gradient ascent. 2 ball centered at u of radius R. the 2,∞ ball centered at U of radius R. For any function f : R d → R, ∇f denotes the gradient vector. We define the standard normal distribution as N (0, 1), and the standard multivariate normal distribution as N (0, I d ). We use S d-1 to denote the unit sphere in d dimensions. We use the standard O-notation (O and Ω). Problem Setup Let X ⊆ R d and Y denote the input space and the label space, respectively. In this paper, we focus on the binary classification setting where Y = -1, +1. We assume that the data (x, y) is drawn from an unknown joint distribution D on X × Y. For a function f w : X → Y parameterized by w in
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- The Double-Edged Sword of Implicit Bias: Generalization vs. Robustness in ReLU NetworksSpencer Frei, Gal Vardi, Peter L. Bartlett, Nati SrebroNeurIPS 2023 · 25 citations
- Beyond the Universal Law of Robustness: Sharper Laws for Random Features and Neural Tangent KernelsSimone Bombari, Shayan Kiyani, Marco MondelliICML 2023 · 13 citations
- Adversarial Reprogramming RevisitedMatthias Englert, Ranko LazicNeurIPS 2022 · 13 citations
- Adversarial Examples Exist in Two-Layer ReLU Networks for Low Dimensional Linear SubspacesOdelia Melamed, Gilad Yehudai, Gal VardiNeurIPS 2023 · 9 citations
- Theoretical Analysis of Robust Overfitting for Wide DNNs: An NTK ApproachShaopeng Fu, Di WangICLR 2024 · 9 citations
Builds on8
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Adversarial Attacks Against Automatic Speech Recognition Systems via Psychoacoustic HidingLea Schönherr, Katharina Kohls, Steffen Zeiler, Thorsten Holz et al.NDSS 2019 · 315 citations
- Polylogarithmic width suffices for gradient descent to achieve arbitrarily small test error with shallow ReLU networksZiwei Ji, Matus TelgarskyICLR 2020 · 193 citations
- Generalization Error Bounds of Gradient Descent for Learning Over-Parameterized Deep ReLU NetworksYuan Cao, Quanquan GuAAAI 2020 · 168 citations
Related papers
- A single gradient step finds adversarial examples on random two-layers neural networksSébastien Bubeck, Yeshwanth Cherapanamjeri, Gauthier Gidel, Remi Tachet des CombesNeurIPS 2021 · 31 citations
- Width Independent Bounds for the Local Lipschitz Constant of Deep Neural Networks at Random Initialization and after Lazy TrainingApostolos Evangelidis, Felix KrahmerICML 2026
- Adversarial Training from Mean Field PerspectiveSoichiro Kumano, Hiroshi Kera, Toshihiko YamasakiNeurIPS 2023 · 2 citations
- Benign Overfitting in Deep Neural Networks under Lazy TrainingZhenyu Zhu, Fanghui Liu, Grigorios Chrysos, Francesco Locatello et al.ICML 2023 · 12 citations
- Adversarial Defense via Learning to Generate Diverse AttacksYunseok Jang, Tianchen Zhao, Seunghoon Hong, Honglak LeeICCV 2019 · 88 citations
