NeurIPS 2020spotlight36 citations
Most ReLU Networks Suffer from $\ell^2$ Adversarial Perturbations
Abstract
We consider ReLU networks with random weights, in which the dimension decreases at each layer. We show that for most such networks, most examples $x$ admit an adversarial perturbation at an Euclidean distance of $O\left(\frac{\|x\|}{\sqrt{d}}\right)$, where $d$ is the input dimension. Moreover, this perturbation can be found via gradient flow, as well as gradient descent with sufficiently small steps. This result can be seen as an explanation to the abundance of adversarial examples, and to the fact that they are found via gradient descent.
BibTeX
@inproceedings{NEURIPS2020_497476fe,
author = {Daniely, Amit and Shacham, Hadas},
booktitle = {Advances in Neural Information Processing Systems},
editor = {H. Larochelle and M. Ranzato and R. Hadsell and M.F. Balcan and H. Lin},
pages = {6629--6636},
publisher = {Curran Associates, Inc.},
title = {Most ReLU Networks Suffer from \textbackslash ell\^{}2 Adversarial Perturbations},
url = {https://proceedings.neurips.cc/paper_files/paper/2020/file/497476fe61816251905e8baafdf54c23-Paper.pdf},
volume = {33},
year = {2020}
}