English

On the interplay of adversarial robustness and architecture components: patches, convolution and attention

Computer Vision and Pattern Recognition 2022-09-16 v1 Machine Learning

Abstract

In recent years novel architecture components for image classification have been developed, starting with attention and patches used in transformers. While prior works have analyzed the influence of some aspects of architecture components on the robustness to adversarial attacks, in particular for vision transformers, the understanding of the main factors is still limited. We compare several (non)-robust classifiers with different architectures and study their properties, including the effect of adversarial training on the interpretability of the learnt features and robustness to unseen threat models. An ablation from ResNet to ConvNeXt reveals key architectural changes leading to almost 10%10\% higher \ell_\infty-robustness.

Keywords

Cite

@article{arxiv.2209.06953,
  title  = {On the interplay of adversarial robustness and architecture components: patches, convolution and attention},
  author = {Francesco Croce and Matthias Hein},
  journal= {arXiv preprint arXiv:2209.06953},
  year   = {2022}
}

Comments

Presented at the "New Frontiers in Adversarial Machine Learning" Workshop at ICML 2022