压缩性与对抗鲁棒性存在根本矛盾,压缩会暴露模型敏感方向。
On the Interaction of Compressibility and Adversarial Robustness
- 分析神经元稀疏与谱压缩对表示空间的影响
- 发现压缩引发少数敏感方向,易被攻击利用
- 适用于关注模型效率与安全性的研究人员
现代神经网络需同时满足训练拟合、泛化能力、参数与计算效率以及对抗鲁棒性等多重目标。尽管压缩性和鲁棒性各自研究充分,二者之间的相互作用仍缺乏统一理解。本文建立了一个系统框架,分析神经元级稀疏性与谱压缩等形式的压缩如何影响对抗鲁棒性。研究表明,这些压缩形式会在表示空间中引入少量高度敏感的方向,攻击者可借此构造有效扰动。理论分析揭示了一个简洁而具启发性的鲁棒性上界,说明神经元和谱压缩通过影响学习表示,分别影响 $L_ty$ 和 $L_2$ 鲁棒性。关键的是,此类脆弱性不依赖压缩实现方式——无论通过正则化、架构偏置或隐式学习动态均存在。在合成与真实任务上的实证验证确认了理论预测,并进一步表明这些脆弱性在对抗训练与迁移学习下依然存在,且促成通用对抗扰动的出现。研究揭示了结构化压缩与鲁棒性间的根本张力,为设计高效且安全的模型提供新路径。
原文摘要 · Abstract (English)
Modern neural networks are expected to simultaneously satisfy a host of desirable properties: accurate fitting to training data, generalization to unseen inputs, parameter and computational efficiency, and robustness to adversarial perturbations. While compressibility and robustness have each been studied extensively, a unified understanding of their interaction still remains elusive. In this work, we develop a principled framework to analyze how different forms of compressibility - such as neuron-level sparsity and spectral compressibility - affect adversarial robustness. We show that these forms of compression can induce a small number of highly sensitive directions in the representation space, which adversaries can exploit to construct effective perturbations. Our analysis yields a simple yet instructive robustness bound, revealing how neuron and spectral compressibility impact $L_\infty$ and $L_2$ robustness via their effects on the learned representations. Crucially, the vulnerabilities we identify arise irrespective of how compression is achieved - whether via regularization, architectural bias, or implicit learning dynamics. Through empirical evaluations across synthetic and realistic tasks, we confirm our theoretical predictions, and further demonstrate that these vulnerabilities persist under adversarial training and transfer learning, and contribute to the emergence of universal adversarial perturbations. Our findings show a fundamental tension between structured compressibility and robustness, and suggest new pathways for designing models that are both efficient and secure.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。