{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/demystifying-causal-features-on-adversarial","title":"Demystifying Causal Features on Adversarial Examples and Causal Inoculation for Robust Network by Adversarial Instrumental Variable Regression","arxiv_id":"2303.01052","date":"2023-03-02","proceeding":"CVPR 2023 1","authors":["Junho Kim","Byung-Kwan Lee","Yong Man Ro"],"abstract":"The origin of adversarial examples is still inexplicable in research fields, and it arouses arguments from various viewpoints, albeit comprehensive investigations. In this paper, we propose a way of delving into the unexpected vulnerability in adversarially trained networks from a causal perspective, namely adversarial instrumental variable (IV) regression. By deploying it, we estimate the causal relation of adversarial prediction under an unbiased environment dissociated from unknown confounders. Our approach aims to demystify inherent causal features on adversarial examples by leveraging a zero-sum optimization game between a casual feature estimator (i.e., hypothesis model) and worst-case counterfactuals (i.e., test function) disturbing to find causal features. Through extensive analyses, we demonstrate that the estimated causal features are highly related to the correct prediction for adversarial robustness, and the counterfactuals exhibit extreme features significantly deviating from the correct prediction. In addition, we present how to effectively inoculate CAusal FEatures (CAFE) into defense networks for improving adversarial robustness.","url_abs":"https://arxiv.org/abs/2303.01052v1","url_pdf":"https://arxiv.org/pdf/2303.01052v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"demystifying-causal-features-on-adversarial","repo_url":"https://github.com/ByungKwanLee/Causal-Adversarial-Instruments","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-robustness","task_name":"Adversarial Robustness"},{"task_slug":"prediction","task_name":"Prediction"}],"methods":[{"method_slug":"counterfactuals","method_name":"Counterfactuals"},{"method_slug":"test","method_name":"Test"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2303.01052","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2303.01052"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/ByungKwanLee/Causal-Adversarial-Instruments","reach":null}],"summary":{"ran":3},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"5bab3e0cdb97094e","entry":"CausalIV","repo":"ByungKwanLee/Causal-Adversarial-Instruments","repo_kind":"official","path":"models/instrument_network.py","file_url":"https://github.com/ByungKwanLee/Causal-Adversarial-Instruments/blob/HEAD/models/instrument_network.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"5bab3e0cdb97094e"}},{"code_sha256_prefix":"fc7c03207448ef0a","entry":"conv_bn_relu","repo":"ByungKwanLee/Causal-Adversarial-Instruments","repo_kind":"official","path":"models/instrument_network.py","file_url":"https://github.com/ByungKwanLee/Causal-Adversarial-Instruments/blob/HEAD/models/instrument_network.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"fc7c03207448ef0a"}},{"code_sha256_prefix":"44b14c24167e2384","entry":"deconv_bn_relu","repo":"ByungKwanLee/Causal-Adversarial-Instruments","repo_kind":"official","path":"models/instrument_network.py","file_url":"https://github.com/ByungKwanLee/Causal-Adversarial-Instruments/blob/HEAD/models/instrument_network.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"44b14c24167e2384"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}