arXiv AI

GRAPE: Guided Parameter-Space Evolution for Compact Adversarial Robustness

arXiv:2606. 14865v1 Announce Type: cross Abstract: Adversarial Training (AT) improves neural network robustness, but most methods train a fixed parameter space from the start.

arXiv Machine Learning
Jun 26

Over-parameterization and Adversarial Robustness in Neural Networks: An Overview and Empirical Analysis

arXiv:2406. 10090v3 Announce Type: replace Abstract: Thanks to their extensive capacity, over-parameterized neural networks exhibit superior predictive capabilities and generalization.

By Srishti Gupta, Zhang Chen, Luca Demetrio, Fabio Brau, Xiaoyi Feng, Zhaoqiang Xia, Antonio Emanuele Cin\`a, Maura Pintor, Luca Oneto, Ambra Demontis, Battista Biggio, Fabio Roli
arXiv AI
Jun 2

SORA: Free Second-Order Attacks in Fast Adversarial Training

arXiv:2606. 00738v1 Announce Type: cross Abstract: Adversarial Training (AT) is a leading defense against adversarial examples but often suffers from Catastrophic Overfitting (CO) in efficient single-step variants, where robustness to multi-step attacks collapses despite high single-step performance.

By Mazdak Teymourian, Ramtin Moslemi, Farzan Rahmani, Mohammad Hossein Rohban
arXiv AI
4d ago

Towards One-for-All Robustness Across a Continuum of Threat Levels

The paper introduces the Threat Conditional Network (TCN), a model that achieves robust performance across a continuous range of adversarial threat levels. TCN splits representation learning into a threat‑invariant backbone and a lightweight threat‑conditional adaptor, using Fourier‑based embeddings and channel‑wise affine modulation to condition on perturbation budgets. Experiments on CIFAR‑10, CIFAR‑100, and Tiny‑ImageNet demonstrate that TCN matches or exceeds ensembles of budget‑specialized models while adding only 4.6% more parameters, and it generalizes to unseen budgets and mismatched threat conditions.

By Zhichao Hou, Xiaorui Liu
arXiv AI
Aug 6

Dynamic Jailbreaking Attack

arXiv:2510. 02422v4 Announce Type: replace-cross Abstract: Existing gradient-based jailbreak attacks typically optimize a fixed-length adversarial suffix toward a predefined target response with a static optimization strategy.

By Kedong Xiu, Yunhan Yang, Churui Zeng, Tianhang Zheng, Xinzhe Huang, Di Wang, Puning Zhao, Zhan Qin, Kui Ren