Pith. sign in

REVIEW 4 cited by

Adversarial Robustness May Be at Odds With Simplicity

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1901.00532 v1 pith:FE4CECTC submitted 2019-01-02 cs.LG cs.CCstat.ML

classification cs.LGcs.CCstat.ML
keywords classifiersclassificationaccuracyhighrobustsimpleadversarialcomplex
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
abstract

Current techniques in machine learning are so far are unable to learn classifiers that are robust to adversarial perturbations. However, they are able to learn non-robust classifiers with very high accuracy, even in the presence of random perturbations. Towards explaining this gap, we highlight the hypothesis that $\textit{robust classification may require more complex classifiers (i.e. more capacity) than standard classification.}$ In this note, we show that this hypothesis is indeed possible, by giving several theoretical examples of classification tasks and sets of "simple" classifiers for which: (1) There exists a simple classifier with high standard accuracy, and also high accuracy under random $\ell_\infty$ noise. (2) Any simple classifier is not robust: it must have high adversarial loss with $\ell_\infty$ perturbations. (3) Robust classification is possible, but only with more complex classifiers (exponentially more complex, in some examples). Moreover, $\textit{there is a quantitative trade-off between robustness and standard accuracy among simple classifiers.}$ This suggests an alternate explanation of this phenomenon, which appears in practice: the tradeoff may occur not because the classification task inherently requires such a tradeoff (as in [Tsipras-Santurkar-Engstrom-Turner-Madry `18]), but because the structure of our current classifiers imposes such a tradeoff.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Adversarial Training from Mean Field Perspective

    cs.LG 2025-05 reject novelty 7.0 of 10

    A mean field framework for random ReLU networks yields adversarial-loss bounds and predicts that adversarial training shrinks weights, hurts vanilla depth, and is rescued by residual connections and width.

  2. Nearly Tight Bounds for Robust Proper Learning of Halfspaces with a Margin

    cs.LG 2019-08 accept novelty 7.0 of 10

    Constant-factor approximate proper learning of large-margin halfspaces is essentially settled: an optimal-sample 2^{Õ(1/γ²)}-time learner, plus an ETH-based 2^{(1/γ)^{2-o(1)}} runtime barrier for any proper learner.

  3. Adversarially Robust Spiking Neural Networks with Sparse Connectivity

    cs.NE 2025-05 conditional novelty 6.0 of 10

    A conversion pipeline turns robustly trained, pruned artificial networks into sparse spiking networks that keep adversarial robustness and cut stored weights by up to 100x.

  4. Intriguing Properties of Robust Classification

    cs.CV 2024-12 conditional novelty 6.0 of 10

    A new no-free-lunch construction and empirical scaling study argue that robust classification can require exponentially more data than standard classification, and that dataset size largely drives certified robust accuracy.

Pith tools