arXiv:2410. 07719v4 Announce Type: replace Abstract: Despite being widely adopted as a canonical framework for learning robust models, adversarial training suffers from robust overfitting.
By Yuelin Xu, Xiao Zhang
arXiv:2607. 05536v1 Announce Type: cross Abstract: Randomized smoothing has emerged as a scalable technique for certifying the adversarial robustness of classifiers.
By Jie Zhang, Natalie Frank
arXiv:2510. 09288v2 Announce Type: replace-cross Abstract: The vulnerability of machine learning models to adversarial attacks remains a critical societal security challenge.
By Pablo G. Arce, Roi Naveiro, David R\'ios Insua
arXiv:2608.21488v1 Announce Type: cross
Abstract: While machine learning models have demonstrated strong performance in many domains, these models have shown profound vulnerabilities when they are ex...
By Mohammad Meymani, Roozbeh Razavi-Far
arXiv:2606. 31653v1 Announce Type: cross Abstract: Certified training aims to produce models whose predictions can be formally verified against adversarial perturbations, typically by optimising upper bounds on the worst-case loss over an allowed perturbation set.
By Matteo Melis, Jesus Martinez Del Rincon, Vishal Sharma
arXiv:2606. 01437v1 Announce Type: cross Abstract: Deep Neural Networks (DNNs) are highly susceptible to adversarial perturbations, leading to extensive research on robustness for safety-critical applications.
By Daniel Sadig, Mohammadreza Maleki, Hamed Karimi, Reza Samavi
The paper introduces a penalized distributionally robust optimization framework that allows an adversary to choose any distribution while incurring a Wasserstein penalty for deviating from the empirical distribution. It shows that the adversary’s problem can be reformulated as optimizing transport maps that push empirical samples to adversarial ones, proving that optimal maps are cyclically monotone. The authors argue that standard per-sample adversarial training violates this property and propose two remedies—multi-start particle ascent and input-convex neural network parameterization—to enforce cyclical monotonicity, demonstrating improved robustness and generalization in experiments on regression, image classification, and control tasks.
By Alireza Abdollahpoorrostam, Ehsan Sharifian, Buse \c{S}en, Marco Cuturi, Daniel Kuhn
The paper rigorously analyzes the statistical and learning-theoretic properties of adversarial training models for classification, focusing on empirical optimal partial transport. It establishes two central limit theorems—one centered at the expected empirical value and another at the population value with smoothing—by leveraging the uniqueness of optimal potentials across various optimal transport formulations and empirical process theory. In the binary setting, the authors prove uniqueness of the optimal potential via a connection to multi-marginal optimal transport, and as additional results they derive stability of the saddle point, sample complexity, and concentration bounds for generalization error.
By Kim Jakwang, Kwon Dohyun
arXiv:2607. 03075v1 Announce Type: new Abstract: Safety-critical applications require classifiers that are both robust and reliable.
By Nicolas Sournac, Ahmed Baha Ben Jmaa, Bertrand Braeckeveldt
arXiv:2406. 10090v3 Announce Type: replace Abstract: Thanks to their extensive capacity, over-parameterized neural networks exhibit superior predictive capabilities and generalization.
By Srishti Gupta, Zhang Chen, Luca Demetrio, Fabio Brau, Xiaoyi Feng, Zhaoqiang Xia, Antonio Emanuele Cin\`a, Maura Pintor, Luca Oneto, Ambra Demontis, Battista Biggio, Fabio Roli
arXiv:2606. 00320v1 Announce Type: new Abstract: We present an online, distribution-free framework for controlling the Conditional Value-at-Risk (CVaR), extending conformal tail risk control to non-stationary and adversarial environments.
By Catherine Chen, Jingyan Shen, Zhun Deng, Lihua Lei