Pith. sign in

REVIEW 2 cited by

Do Adversarially Robust ImageNet Models Transfer Better?

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2007.08489 v2 pith:BHNNYW4Q submitted 2020-07-16 cs.CV cs.LGstat.ML

classification cs.CVcs.LGstat.ML
keywords modelstransferlearningbetterrobustadversariallystandardaccuracy
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Transfer learning is a widely-used paradigm in deep learning, where models pre-trained on standard datasets can be efficiently adapted to downstream tasks. Typically, better pre-trained models yield better transfer results, suggesting that initial accuracy is a key aspect of transfer learning performance. In this work, we identify another such aspect: we find that adversarially robust models, while less accurate, often perform better than their standard-trained counterparts when used for transfer learning. Specifically, we focus on adversarially robust ImageNet classifiers, and show that they yield improved accuracy on a standard suite of downstream classification tasks. Further analysis uncovers more differences between robust and standard models in the context of transfer learning. Our results are consistent with (and in fact, add to) recent hypotheses stating that robustness leads to improved feature representations. Our code and models are available at https://github.com/Microsoft/robust-models-transfer .

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Adversarial Examples Are Not Bugs, They Are Superposition

    cs.LG 2025-08 unverdicted novelty 6.0 of 10

    The paper argues that adversarial examples arise from superposition, and shows that changing superposition changes robustness and vice versa in toy models and ResNet18.

  2. Killing it with Zero-Shot: Adversarially Robust Novelty Detection

    cs.LG 2025-01 conditional novelty 5.0 of 10

    Using features from an adversarially robust ImageNet model with a k-nearest-neighbor score gives state-of-the-art adversarial robustness in novelty detection on several image benchmarks.

Pith tools