{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,31]],"date-time":"2026-01-31T03:15:31Z","timestamp":1769829331392,"version":"3.49.0"},"reference-count":41,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2024,1,11]],"date-time":"2024-01-11T00:00:00Z","timestamp":1704931200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Comput. Sci."],"abstract":"<jats:p>The adversarial risk of a machine learning model has been widely studied. Most previous studies assume that the data lie in the whole ambient space. We propose to take a new angle and take the manifold assumption into consideration. Assuming data lie in a manifold, we investigate two new types of adversarial risk, the normal adversarial risk due to perturbation along normal direction and the in-manifold adversarial risk due to perturbation within the manifold. We prove that the classic adversarial risk can be bounded from both sides using the normal and in-manifold adversarial risks. We also show a surprisingly pessimistic case that the standard adversarial risk can be non-zero even when both normal and in-manifold adversarial risks are zero. We finalize the study with empirical studies supporting our theoretical results. Our results suggest the possibility of improving the robustness of a classifier without sacrificing model accuracy, by only focusing on the normal adversarial risk.<\/jats:p>","DOI":"10.3389\/fcomp.2023.1274695","type":"journal-article","created":{"date-parts":[[2024,1,11]],"date-time":"2024-01-11T05:03:45Z","timestamp":1704949425000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Manifold-driven decomposition for adversarial robustness"],"prefix":"10.3389","volume":"5","author":[{"given":"Wenjia","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yikai","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoling","family":"Hu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yi","family":"Yao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mayank","family":"Goswami","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chao","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dimitris","family":"Metaxas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1965","published-online":{"date-parts":[[2024,1,11]]},"reference":[{"key":"B1","article-title":"\u201cOn robustness to adversarial examples and polynomial optimization,\u201d","author":"Awasthi","year":"2019","journal-title":"Advances in Neural Information Processing Systems"},{"key":"B2","volume-title":"Topology and Geometry, Volume 139","author":"Bredon","year":"2013"},{"key":"B3","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1109\/SP.2017.49","article-title":"\u201cTowards evaluating the robustness of neural networks,\u201d","volume-title":"2017 IEEE Symposium on Security and Privacy (sp)","author":"Carlini","year":"2017"},{"key":"B4","article-title":"Unlabeled data improves adversarial robustness","author":"Carmon","year":"2019","journal-title":"arXiv"},{"key":"B5","volume-title":"Algorithms for Manifold Learning","author":"Cayton","year":"2005"},{"key":"B6","doi-asserted-by":"publisher","first-page":"124","DOI":"10.1016\/j.comgeo.2005.10.006","article-title":"Provable surface reconstruction from noisy samples","volume":"35","author":"Dey","year":"2006","journal-title":"Comp. Geomet"},{"key":"B7","first-page":"1646","article-title":"\u201cGeneralized no free lunch theorem for adversarial robustness,\u201d","volume-title":"International Conference on Machine Learning","author":"Dohmatob","year":"2019"},{"key":"B8","first-page":"285","article-title":"\u201cTriangulating topological spaces,\u201d","volume-title":"Proceedings of the Tenth Annual Symposium on Computational Geometry","author":"Edelsbrunner","year":"1994"},{"key":"B9","article-title":"\u201cAdversarial vulnerability for any classifier,\u201d","volume-title":"Advances in Neural Information Processing Systems","author":"Fawzi","year":"2018"},{"key":"B10","article-title":"Adversarial spheres","author":"Gilmer","year":"2018","journal-title":"arXiv"},{"key":"B11","article-title":"Uncovering the limits of adversarial training against norm-bounded adversarial examples","author":"Gowal","year":"2020","journal-title":"arXiv"},{"key":"B12","first-page":"631","article-title":"\u201cWhen nas meets robustness: In search of robust architectures against adversarial attacks,\u201d","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Guo","year":"2020"},{"key":"B13","first-page":"770","article-title":"\u201cDeep residual learning for image recognition,\u201d","volume-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","author":"He","year":"2016"},{"key":"B14","doi-asserted-by":"publisher","first-page":"1097","DOI":"10.1145\/3065386","article-title":"Imagenet classification with deep convolutional neural networks","volume":"25","author":"Krizhevsky","year":"2012","journal-title":"Adv. Neural Inform. Proc. Syst"},{"key":"B15","doi-asserted-by":"publisher","first-page":"13054","DOI":"10.1109\/TPAMI.2023.3286772","article-title":"Interpolated joint space adversarial training for robust and generalizable defenses","volume":"45","author":"Lau","year":"2023","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell"},{"key":"B16","first-page":"1071","article-title":"\u201cLearning neural network policies with guided policy search under unknown dynamics,\u201d","volume-title":"NIPS","author":"Levine","year":"2014"},{"key":"B17","first-page":"3487","article-title":"Dual manifold adversarial robustness: Defense against lp and non-lp adversarial attacks","volume":"33","author":"Lin","year":"2020","journal-title":"Adv. Neural Inform. Proc. Syst"},{"key":"B18","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv preprint"},{"key":"B19","doi-asserted-by":"crossref","first-page":"7559","DOI":"10.1109\/ICRA.2018.8463189","article-title":"\u201cNeural network dynamics for model-based deep reinforcement learning with model-free fine-tuning,\u201d","volume-title":"2018 IEEE International Conference on Robotics and Automation (ICRA)","author":"Nagabandi","year":"2018"},{"key":"B20","first-page":"1786","article-title":"\u201cSample complexity of testing the manifold hypothesis,\u201d","volume-title":"Proceedings of the 23rd International Conference on Neural Information Processing Systems","author":"Narayanan","year":"2010"},{"key":"B21","doi-asserted-by":"publisher","first-page":"419","DOI":"10.1007\/s00454-008-9053-2","article-title":"Finding the homology of submanifolds with high confidence from random samples","volume":"39","author":"Niyogi","year":"2008","journal-title":"Discrete"},{"key":"B22","first-page":"7909","article-title":"\u201cUnderstanding and mitigating the tradeoff between robustness and accuracy,\u201d","author":"Raghunathan","year":"2020","journal-title":"Proceedings of the 37th International Conference on Machine Learning"},{"key":"B23","first-page":"8093","article-title":"\u201cOverfitting in adversarially robust deep learning,\u201d","volume-title":"International Conference on Machine Learning","author":"Rice","year":"2020"},{"key":"B24","first-page":"2294","article-title":"The manifold tangent classifier","volume":"24","author":"Rifai","year":"2011","journal-title":"Adv. Neural Inform. Proc. Syst"},{"key":"B25","first-page":"12","article-title":"\u201cThink globally, fit locally: unsupervised learning of low dimensional manifolds,\u201d","volume-title":"Departmental Papers (CIS)","author":"Saul","year":"2003"},{"key":"B26","author":"Shafahi","year":"2019"},{"key":"B27","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1016\/j.neucom.2018.04.027","article-title":"Understanding adversarial training: increasing local stability of supervised models through robust optimization","volume":"307","author":"Shaham","year":"2018","journal-title":"Neurocomputing"},{"key":"B28","article-title":"\u201cThe dimpled manifold model of adversarial examples in machine learning,\u201d","author":"Shamir","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"B29","first-page":"6976","article-title":"\u201cDisentangling adversarial robustness and generalization,\u201d","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Stutz","year":"2019"},{"key":"B30","first-page":"631","article-title":"\u201cIs robustness the cost of accuracy?-A comprehensive study on the robustness of 18 deep image classification models,\u201d","volume-title":"Proceedings of the European Conference on Computer Vision (ECCV)","author":"Su","year":"2018"},{"key":"B31","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv"},{"key":"B32","article-title":"A boundary tilting persepective on the phenomenon of adversarial examples","author":"Tanay","year":"2016","journal-title":"arXiv"},{"key":"B33","doi-asserted-by":"publisher","first-page":"2319","DOI":"10.1126\/science.290.5500.2319","article-title":"A global geometric framework for nonlinear dimensionality reduction","volume":"290","author":"Tenenbaum","year":"2000","journal-title":"Science"},{"key":"B34","article-title":"Robustness may be at odds with accuracy","author":"Tsipras","year":"2018","journal-title":"arXiv"},{"key":"B35","article-title":"\u201cAttention is all you need,\u201d","author":"Vaswani","year":"2017","journal-title":"Advances in Neural Information Processing Systems"},{"key":"B36","article-title":"Google's neural machine translation system: bridging the gap between human and machine translation","author":"Wu","year":"2016","journal-title":"arXiv"},{"key":"B37","first-page":"819","article-title":"\u201cAdversarial examples improve image recognition,\u201d","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Xie","year":"2020"},{"key":"B38","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1007\/978-3-030-63823-8","article-title":"A closer look at accuracy vs. robustness","volume":"33","author":"Yang","year":"2020","journal-title":"Adv. Neural Inform. Proc. Syst"},{"key":"B39","first-page":"10676","article-title":"\u201cTangent-normal adversarial regularization for semi-supervised learning,\u201d","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Yu","year":"2019"},{"key":"B40","first-page":"7472","article-title":"\u201cTheoretically principled trade-off between robustness and accuracy,\u201d","volume-title":"International Conference on Machine Learning","author":"Zhang","year":"2019"},{"key":"B41","first-page":"11598","article-title":"\u201cA manifold view of adversarial risk,\u201d","volume-title":"International Conference on Artificial Intelligence and Statistics","author":"Zhang","year":"2022"}],"container-title":["Frontiers in Computer Science"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2023.1274695\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,11]],"date-time":"2024-01-11T05:04:14Z","timestamp":1704949454000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fcomp.2023.1274695\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1,11]]},"references-count":41,"alternative-id":["10.3389\/fcomp.2023.1274695"],"URL":"https:\/\/doi.org\/10.3389\/fcomp.2023.1274695","relation":{},"ISSN":["2624-9898"],"issn-type":[{"value":"2624-9898","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,1,11]]},"article-number":"1274695"}}