English

Adversarial Robustness is at Odds with Lazy Training

Machine Learning 2022-10-19 v2 Cryptography and Security Machine Learning

Abstract

Recent works show that adversarial examples exist for random neural networks [Daniely and Schacham, 2020] and that these examples can be found using a single step of gradient ascent [Bubeck et al., 2021]. In this work, we extend this line of work to "lazy training" of neural networks -- a dominant model in deep learning theory in which neural networks are provably efficiently learnable. We show that over-parametrized neural networks that are guaranteed to generalize well and enjoy strong computational guarantees remain vulnerable to attacks generated using a single step of gradient ascent.

Keywords

Cite

@article{arxiv.2207.00411,
  title  = {Adversarial Robustness is at Odds with Lazy Training},
  author = {Yunjuan Wang and Enayat Ullah and Poorya Mianjy and Raman Arora},
  journal= {arXiv preprint arXiv:2207.00411},
  year   = {2022}
}

Comments

NeurIPS 2022

R2 v1 2026-06-24T12:11:06.415Z