Do Perceptually Aligned Gradients Imply Robustness?
Roy Ganz, Bahjat Kawar, Michael Elad
摘要
Adversarially robust classifiers possess a trait that non-robust models do not -Perceptually Aligned Gradients (PAG). Their gradients with respect to the input align well with human perception. Several works have identified PAG as a byproduct of robust training, but none have considered it as a standalone phenomenon nor studied its own implications. In this work, we focus on this trait and test whether Perceptually Aligned Gradients imply Robustness. To this end, we develop a novel objective to directly promote PAG in training classifiers and examine whether models with such gradients are more robust to adversarial attacks. Extensive experiments on multiple datasets and architectures validate that models with aligned gradients exhibit significant robustness, exposing the surprising bidirectional connection between PAG and robustness. Lastly, we show that better gradient alignment leads to increased robustness and harness this observation to boost the robustness of existing adversarial training techniques. Our code is available at https: //github.com/royg27/PAG-ROB .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Adversarial Vulnerability from Interference Between Features in SuperpositionEdward Stevinson, Lucas Prieto, Melih Barsbey, Tolga BirdalICML 2026 · 被引用 4 次
- Enhancing Consistency-Based Image Generation via Adversarialy-Trained Classification and Energy-Based DiscriminationShelly Golan, Roy Ganz, Michael EladNeurIPS 2024 · 被引用 3 次
- Implicit Inversion turns CLIP into a DecoderAntonio D'Orazio, Maria Rosaria Briglia, Donato Crisostomi, Dario Loi 等ICLR 2026 · 被引用 3 次
- Counterfactual Explanations on Robust Perceptual GeodesicsEslam Zaher, Dr Maciej Trzaskowski, Quan Nguyen, Fred RoostaICLR 2026 · 被引用 2 次
- Compressed Image Generation with Denoising Diffusion Codebook ModelsGuy Ohayon, Hila Manor, Tomer Michaeli, Michael EladICML 2025
它引用的顶会 Paper24
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 被引用 35,902 次
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Diffusion Models Beat GANs on Image SynthesisPrafulla Dhariwal, Alexander Quinn NicholNeurIPS 2021 · 被引用 13,211 次
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser 等CVPR 2022 · 被引用 13,123 次
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
相关 Paper
- Which Models have Perceptually-Aligned Gradients? An Explanation via Off-Manifold RobustnessSuraj Srinivas, Sebastian Bordt, Himabindu LakkarajuNeurIPS 2023 · 被引用 24 次
- Balancing Generalization and Robustness in Adversarial Training via Steering through Clean and Adversarial Gradient DirectionsHaoyu Tong, Xiaoyu Zhang, Yulin Jin, Jian Lou 等ACM MM 2024 · 被引用 2 次
- Perceptual Adversarial Robustness: Defense Against Unseen Threat ModelsCassidy Laidlaw, Sahil Singla, Soheil FeiziICLR 2021 · 被引用 217 次
- What It Thinks Is Important Is Important: Robustness Transfers Through Input GradientsAlvin Chan, Yi Tay, Yew-Soon OngCVPR 2020
- Failure Cases Are Better Learned but Boundary Says Sorry: Facilitating Smooth Perception Change for Accuracy-Robustness Trade-Off in Adversarial TrainingYanyun Wang, Li LiuICCV 2025 · 被引用 1 次
