Pith. sign in

REVIEW 1 cited by

Robust Principles: Architectural Design Principles for Adversarially Robust CNNs

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2308.16258 v2 pith:Y6MJ7HRW submitted 2023-08-30 cs.CV

classification cs.CV
keywords designprinciplesrobustarchitecturaladversarialcnnsaccomplishaccuracy
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Our research aims to unify existing works' diverging opinions on how architectural components affect the adversarial robustness of CNNs. To accomplish our goal, we synthesize a suite of three generalizable robust architectural design principles: (a) optimal range for depth and width configurations, (b) preferring convolutional over patchify stem stage, and (c) robust residual block design through adopting squeeze and excitation blocks and non-parametric smooth activation functions. Through extensive experiments across a wide spectrum of dataset scales, adversarial training methods, model parameters, and network design spaces, our principles consistently and markedly improve AutoAttack accuracy: 1-3 percentage points (pp) on CIFAR-10 and CIFAR-100, and 4-9 pp on ImageNet. The code is publicly available at https://github.com/poloclub/robust-principles.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Towards Million-Scale Adversarial Robustness Evaluation With Stronger Individual Attacks

    cs.LG 2024-11 conditional novelty 6.0 of 10

    PMA, a probability-margin loss attack, consistently outperforms existing individual white-box attacks, and a one-million-image evaluation shows much lower robust accuracy than small-scale tests.

Pith tools