Adversarial Examples in Random Neural Networks with General Activations
Abstract
A substantial body of empirical work documents the lack of robustness in deep learning models to adversarial examples. Recent theoretical work proved that adversarial examples are ubiquitous in two-layers networks with sub-exponential width and ReLU or smooth activations, and multi-layer ReLU networks with sub-exponential width. We present a result of the same type, with no restriction on width and for general locally Lipschitz continuous activations. More precisely, given a neural network with random weights , and feature vector , we show that an adversarial example can be found with high probability along the direction of the gradient . Our proof is based on a Gaussian conditioning technique. Instead of proving that is approximately linear in a neighborhood of , we characterize the joint distribution of and for .
Keywords
Cite
@article{arxiv.2203.17209,
title = {Adversarial Examples in Random Neural Networks with General Activations},
author = {Andrea Montanari and Yuchen Wu},
journal= {arXiv preprint arXiv:2203.17209},
year = {2023}
}
Comments
36 pages