Pith. sign in

REVIEW 1 cited by

Towards Understanding Adversarial Examples Systematically: Exploring Data Size, Task and Model Factors

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1902.11019 v1 pith:MQ5E3IKH submitted 2019-02-28 cs.LG stat.ML

classification cs.LGstat.ML
keywords adversarialdataexamplesgeneralizationfactorssizestandardtraining
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Most previous works usually explained adversarial examples from several specific perspectives, lacking relatively integral comprehension about this problem. In this paper, we present a systematic study on adversarial examples from three aspects: the amount of training data, task-dependent and model-specific factors. Particularly, we show that adversarial generalization (i.e. test accuracy on adversarial examples) for standard training requires more data than standard generalization (i.e. test accuracy on clean examples); and uncover the global relationship between generalization and robustness with respect to the data size especially when data is augmented by generative models. This reveals the trade-off correlation between standard generalization and robustness in limited training data regime and their consistency when data size is large enough. Furthermore, we explore how different task-dependent and model-specific factors influence the vulnerability of deep neural networks by extensive empirical analysis. Relevant recommendations on defense against adversarial attacks are provided as well. Our results outline a potential path towards the luminous and systematic understanding of adversarial examples.

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. GJDNet: Robust Graph Neural Networks via Joint Disentangled Learning Against Adversarial Attacks

    cs.LG 2026-06 unverdicted novelty 5.0 of 10

    GJDNet proposes feature-driven soft structural disentanglement and a Spherical Decision Boundary to achieve robust node classification on graphs with varying assortativity against adversarial attacks.

Pith tools