{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/proper-measure-for-adversarial-robustness","title":"Measuring Adversarial Robustness using a Voronoi-Epsilon Adversary","arxiv_id":"2005.02540","date":"2020-05-06","proceeding":null,"authors":["Hyeongji Kim","Pekka Parviainen","Ketil Malde"],"abstract":"Previous studies on robustness have argued that there is a tradeoff between accuracy and adversarial accuracy. The tradeoff can be inevitable even when we neglect generalization. We argue that the tradeoff is inherent to the commonly used definition of adversarial accuracy, which uses an adversary that can construct adversarial points constrained by $\\epsilon$-balls around data points. As $\\epsilon$ gets large, the adversary may use real data points from other classes as adversarial examples. We propose a Voronoi-epsilon adversary which is constrained both by Voronoi cells and by $\\epsilon$-balls. This adversary balances between two notions of perturbation. As a result, adversarial accuracy based on this adversary avoids a tradeoff between accuracy and adversarial accuracy on training data even when $\\epsilon$ is large. Finally, we show that a nearest neighbor classifier is the maximally robust classifier against the proposed adversary on the training data.","url_abs":"https://arxiv.org/abs/2005.02540v3","url_pdf":"https://arxiv.org/pdf/2005.02540v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"proper-measure-for-adversarial-robustness","repo_url":"https://github.com/hjk92g/proper_measure_robustness","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"none","reach":null}],"tasks":[{"task_slug":"adversarial-robustness","task_name":"Adversarial Robustness"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2005.02540","atlas_url":"https://app.syntology.ai/?focus=2005.02540","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2005.02540"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/hjk92g/proper_measure_robustness","reach":null}],"summary":{"ran_fixture":1,"ran_honours":2},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"d246a272c925e0f9","entry":"gen_Proj","repo":"hjk92g/proper_measure_robustness","repo_kind":"official","path":"2D_genuine_Proj.py","file_url":"https://github.com/hjk92g/proper_measure_robustness/blob/HEAD/2D_genuine_Proj.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"d246a272c925e0f9"}},{"code_sha256_prefix":"b734bc73895c963b","entry":"ndarray_l1_norm","repo":"hjk92g/proper_measure_robustness","repo_kind":"official","path":"2D_genuine_Proj.py","file_url":"https://github.com/hjk92g/proper_measure_robustness/blob/HEAD/2D_genuine_Proj.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"b734bc73895c963b"}},{"code_sha256_prefix":"63edc9a7cd51fbc3","entry":"ndarray_norm","repo":"hjk92g/proper_measure_robustness","repo_kind":"official","path":"2D_genuine_Proj.py","file_url":"https://github.com/hjk92g/proper_measure_robustness/blob/HEAD/2D_genuine_Proj.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":null,"behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"63edc9a7cd51fbc3"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}