vix.ing · top · new · best · stats · spec

Most ReLU Networks Suffer from ℓ2 Adversarial Perturbations

2020/10/28 by Amit Daniely, Daniely, Amit, Hadas Schacham +1
Computer Science · #Advanced Malware Detection Techniques #Adversarial Robustness in Machine Learning #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Machine Learning (cs.LG) #Machine Learning (stat.ML) #Network Security and Intrusion Detection

paper · pdf · doi:10.48550/arxiv.2010.14927

openalex publication_date 2020/10/28 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

We consider ReLU networks with random weights, in which the dimension decreases at each layer. We show that for most such networks, most examples x admit an adversarial perturbation at an Euclidean distance of O((‖x‖)/(√(d))), where d is the input dimension. Moreover, this perturbation can be found via gradient flow, as well as gradient descent with sufficiently small steps. This result can be seen as an explanation to the abundance of adversarial examples, and to the fact that they are found via gradient descent.

Citations

Related