{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/robustness-may-be-at-odds-with-accuracy","title":"Robustness May Be at Odds with Accuracy","arxiv_id":"1805.12152","date":"2018-05-30","proceeding":"ICLR 2019 5","authors":["Dimitris Tsipras","Shibani Santurkar","Logan Engstrom","Alexander Turner","Aleksander Madry"],"abstract":"We show that there may exist an inherent tension between the goal of adversarial robustness and that of standard generalization. Specifically, training robust models may not only be more resource-consuming, but also lead to a reduction of standard accuracy. We demonstrate that this trade-off between the standard accuracy of a model and its robustness to adversarial perturbations provably exists in a fairly simple and natural setting. These findings also corroborate a similar phenomenon observed empirically in more complex settings. Further, we argue that this phenomenon is a consequence of robust classifiers learning fundamentally different feature representations than standard classifiers. These differences, in particular, seem to result in unexpected benefits: the representations learned by robust models tend to align better with salient data characteristics and human perception.","url_abs":"https://arxiv.org/abs/1805.12152v5","url_pdf":"https://arxiv.org/pdf/1805.12152v5.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"robustness-may-be-at-odds-with-accuracy","repo_url":"https://github.com/AugustineCha/pytorch-adversarial-training-master","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}},{"paper_slug":"robustness-may-be-at-odds-with-accuracy","repo_url":"https://github.com/MadryLab/robust-features-code","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok"}},{"paper_slug":"robustness-may-be-at-odds-with-accuracy","repo_url":"https://github.com/XgDuan/pytorch-adversarial-training-nonexpansive","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}},{"paper_slug":"robustness-may-be-at-odds-with-accuracy","repo_url":"https://github.com/conference-submission-anon/LAT_adversarial_robustness","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok"}},{"paper_slug":"robustness-may-be-at-odds-with-accuracy","repo_url":"https://github.com/louis2889184/adversarial_training","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}},{"paper_slug":"robustness-may-be-at-odds-with-accuracy","repo_url":"https://github.com/louis2889184/pytorch-adversarial-training","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}},{"paper_slug":"robustness-may-be-at-odds-with-accuracy","repo_url":"https://github.com/msingh27/LAT_adversarial_robustness","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"tf","reach":{"status":"ok"}},{"paper_slug":"robustness-may-be-at-odds-with-accuracy","repo_url":"https://github.com/salomonhotegni/MOREL","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"adversarial-robustness","task_name":"Adversarial Robustness"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1805.12152","atlas_url":"https://app.syntology.ai/?focus=1805.12152","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}