Pith. sign in

REVIEW 1 cited by

Pruning Adversarially Robust Neural Networks without Adversarial Examples

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2210.04311 v1 pith:5UQAZA3U submitted 2022-10-09 cs.LG cs.AIcs.CRcs.CV

classification cs.LGcs.AIcs.CRcs.CV
keywords adversarialpruningexamplesmethodsrobustnessattacksefficiencyframework
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Adversarial pruning compresses models while preserving robustness. Current methods require access to adversarial examples during pruning. This significantly hampers training efficiency. Moreover, as new adversarial attacks and training methods develop at a rapid rate, adversarial pruning methods need to be modified accordingly to keep up. In this work, we propose a novel framework to prune a previously trained robust neural network while maintaining adversarial robustness, without further generating adversarial examples. We leverage concurrent self-distillation and pruning to preserve knowledge in the original model as well as regularizing the pruned model via the Hilbert-Schmidt Information Bottleneck. We comprehensively evaluate our proposed framework and show its superior performance in terms of both adversarial robustness and efficiency when pruning architectures trained on the MNIST, CIFAR-10, and CIFAR-100 datasets against five state-of-the-art attacks. Code is available at https://github.com/neu-spiral/PwoA/.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Robustness as Architecture: Designing IQA Models to Withstand Adversarial Perturbations

    cs.CV 2025-06 conditional novelty 5.0 of 10

    An NR-IQA defense built from an FFT-domain orthogonal block, 10% pruning, and fine-tuning lowers adversarial AbsGain on some models with a modest SROCC decline, but the reported gains are mixed across architectures.

Pith tools