2020
Most ReLU Networks Suffer from $\ell^2$ Adversarial Perturbations
NeurIPS 2020spotlight
We consider ReLU networks with random weights, in which the dimension decreases at each layer. We show that for most such networks, most examples $x$ admit an adversarial perturbation at an Euclidean distance of $O\left(\frac{\|x\|}{\sqrt{d}}\right)$, where $d$ is the input dimension. Moreover, this…