Pith. sign in

REVIEW 3 cited by

Adversarially Robust Generalization Just Requires More Unlabeled Data

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1906.00555 v2 pith:LHMX57DT submitted 2019-06-03 cs.LG stat.ML

classification cs.LGstat.ML
keywords datageneralizationrobustunlabeledadversariallypartadversarialstability
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Neural network robustness has recently been highlighted by the existence of adversarial examples. Many previous works show that the learned networks do not perform well on perturbed test data, and significantly more labeled data is required to achieve adversarially robust generalization. In this paper, we theoretically and empirically show that with just more unlabeled data, we can learn a model with better adversarially robust generalization. The key insight of our results is based on a risk decomposition theorem, in which the expected robust risk is separated into two parts: the stability part which measures the prediction stability in the presence of perturbations, and the accuracy part which evaluates the standard classification accuracy. As the stability part does not depend on any label information, we can optimize this part using unlabeled data. We further prove that for a specific Gaussian mixture problem, adversarially robust generalization can be almost as easy as the standard generalization in supervised learning if a sufficiently large amount of unlabeled data is provided. Inspired by the theoretical findings, we further show that a practical adversarial training algorithm that leverages unlabeled data can improve adversarial robust generalization on MNIST and Cifar-10.

Discussion (0). Sign in to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. On the existence of consistent adversarial attacks in high-dimensional linear classification

    stat.ML 2025-06 reject novelty 7.0 of 10

    The authors derive sharp high-dimensional formulas for consistent adversarial errors in linear classifiers and show overparameterization increases vulnerability on correctly classified points while decreasing the over...

  2. Adversarial Training from Mean Field Perspective

    cs.LG 2025-05 reject novelty 7.0 of 10

    A mean field framework for random ReLU networks yields adversarial-loss bounds and predicts that adversarial training shrinks weights, hurts vanilla depth, and is rescued by residual connections and width.

  3. Understanding Adversarial Training with Energy-based Models

    cs.LG 2025-05 conditional novelty 4.0 of 10

    Delta energy, the energy gap between an image and its adversarial counterpart, separates catastrophic from robust overfitting, and penalizing it with the DER regularizer mitigates both while improving generation diversity.

Pith tools