Pith. sign in

REVIEW 1 cited by

On the Effect of Low-Rank Weights on Adversarial Robustness of Neural Networks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1901.10371 v2 pith:352YOWTV submitted 2019-01-29 cs.LG stat.ML

On the Effect of Low-Rank Weights on Adversarial Robustness of Neural Networks

classification cs.LG stat.ML
keywords adversarialnetworksneuralrobustnessdnnslow-rankrobuststructure
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved
0 comments
read the original abstract

Recently, there has been an abundance of works on designing Deep Neural Networks (DNNs) that are robust to adversarial examples. In particular, a central question is which features of DNNs influence adversarial robustness and, therefore, can be to used to design robust DNNs. In this work, this problem is studied through the lens of compression which is captured by the low-rank structure of weight matrices. It is first shown that adversarial training tends to promote simultaneously low-rank and sparse structure in the weight matrices of neural networks. This is measured through the notions of effective rank and effective sparsity. In the reverse direction, when the low rank structure is promoted by nuclear norm regularization and combined with sparsity inducing regularizations, neural networks show significantly improved adversarial robustness. The effect of nuclear norm regularization on adversarial robustness is paramount when it is applied to convolutional neural networks. Although still not competing with adversarial training, this result contributes to understanding the key properties of robust classifiers.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. The Grokked Illusion: True Equilibrium Mitigates Catastrophic Forgetting

    cs.LG 2026-07 conditional novelty 6.0

    High-entropy (equilibrium) neural networks retain old knowledge far better than standard-trained networks after learning noisy data, even when both generalize perfectly.