The paper presents a unified framework for regularization-based robust reinforcement learning by deriving upper bounds on the performance gap between nominal and worst-case policies. These bounds are expressed as a regularization objective plus a KL-divergence penalty, explaining why KL penalties enhance robustness. The authors reformulate robust training as a constrained optimization problem, updating the Lagrange multiplier jointly with the policy to automatically tune regularization, and validate the approach with extensive adversarial evaluations on continuous control tasks.
By Amine Andam, Jamal Bentahar, Mustapha Hedabou
arXiv:2406. 05670v3 Announce Type: replace Abstract: Modern machine learning pipelines leverage large amounts of public data, making it infeasible to guarantee data quality and leaving models open to poisoning and backdoor attacks.
By Philip Sosnin, Mark N. M\"uller, Maximilian Baader, Calvin Tsay, Matthew Wicker
arXiv:2604. 25965v2 Announce Type: replace-cross Abstract: Deep learning models are widely deployed in safety-critical domains, but remain vulnerable to adversarial attacks.
By Yuxuan Hou
arXiv:2502. 11152v4 Announce Type: replace-cross Abstract: The optimization foundations of deep linear networks have recently received significant attention.
By Po Chen, Rujun Jiang, Peng Wang
arXiv:2607. 16329v1 Announce Type: cross Abstract: Lipschitz continuity is a fundamental property of neural networks that characterizes their sensitivity to input perturbations.
By R\'ois\'in Luo, James McDermott, Colm O'Riordan
arXiv:2607. 04145v1 Announce Type: new Abstract: Adversarial attacks guide and provide additional training and test data for both adversarial training and adversarial robustness validation, and expose the 'piecewise linearity' of deep learning based models.
By Naman Goyal, Milan Chaudhari
The paper investigates how the choice of the π parameter in λπ norm-constrained adversarial attacks influences the sparsity and smoothness of the perturbations. By applying two established sparsity metrics and introducing three new smoothness measures—including one based on first-order Taylor approximations—the authors perform extensive experiments on real-world image datasets and various neural network architectures. Their results indicate that λρ norms with π values between 1.3 and 1.5 consistently provide the best balance between sparsity and smoothness, challenging the common use of λ1 or λ2 norms.
By Christof Duhme, Florian Eilers, Xiaoyi Jiang
arXiv:2607. 27995v2 Announce Type: replace-cross Abstract: Adversarial training can improve the robustness of predictive models to bounded perturbations, often at the cost of statistical efficiency.
By Yiling Xie, Xiaoming Huo
arXiv:2608. 09523v1 Announce Type: new Abstract: Deep neural network (DNN) training with stochastic gradient descent (SGD) and its variants achieves strong empirical performance, yet classical optimization theory does not fully explain this success.
By Binchuan Qi
arXiv:2608.29247v1 Announce Type: new
Abstract: Deep neural networks remain highly vulnerable to adversarial perturbations, and adversarial training (AT) has become a widely used approach for improvi...
By Tejaswini Medi, Levan Mikeladze, Margret Keuper
arXiv:2606. 02267v1 Announce Type: new Abstract: The vulnerability of deep neural networks to adversarial examples poses a significant challenge for real-world deployment.
By Nicolas Stalder, Benjamin F. Grewe, Matteo Saponati, Pau Vilimelis Aceituno
The paper introduces a penalized distributionally robust optimization framework that allows an adversary to choose any distribution while incurring a Wasserstein penalty for deviating from the empirical distribution. It shows that the adversary’s problem can be reformulated as optimizing transport maps that push empirical samples to adversarial ones, proving that optimal maps are cyclically monotone. The authors argue that standard per-sample adversarial training violates this property and propose two remedies—multi-start particle ascent and input-convex neural network parameterization—to enforce cyclical monotonicity, demonstrating improved robustness and generalization in experiments on regression, image classification, and control tasks.
By Alireza Abdollahpoorrostam, Ehsan Sharifian, Buse \c{S}en, Marco Cuturi, Daniel Kuhn