{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/robustness-of-bayesian-neural-networks-to","title":"Robustness of Bayesian Neural Networks to Gradient-Based Attacks","arxiv_id":"2002.04359","date":"2020-02-11","proceeding":"NeurIPS 2020 12","authors":["Ginevra Carbone","Matthew Wicker","Luca Laurenti","Andrea Patane","Luca Bortolussi","Guido Sanguinetti"],"abstract":"Vulnerability to adversarial attacks is one of the principal hurdles to the adoption of deep learning in safety-critical applications. Despite significant efforts, both practical and theoretical, the problem remains open. In this paper, we analyse the geometry of adversarial attacks in the large-data, overparametrized limit for Bayesian Neural Networks (BNNs). We show that, in the limit, vulnerability to gradient-based attacks arises as a result of degeneracy in the data distribution, i.e., when the data lies on a lower-dimensional submanifold of the ambient space. As a direct consequence, we demonstrate that in the limit BNN posteriors are robust to gradient-based adversarial attacks. Experimental results on the MNIST and Fashion MNIST datasets with BNNs trained with Hamiltonian Monte Carlo and Variational Inference support this line of argument, showing that BNNs can display both high accuracy and robustness to gradient based adversarial attacks.","url_abs":"https://arxiv.org/abs/2002.04359v3","url_pdf":"https://arxiv.org/pdf/2002.04359v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"robustness-of-bayesian-neural-networks-to","repo_url":"https://github.com/ginevracoal/robustBNNs","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"variational-inference","task_name":"Variational Inference"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2002.04359","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2002.04359"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/ginevracoal/robustBNNs","reach":null}],"summary":{"ran_fixture":1,"ran_honours":2},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":3,"samples":[{"code_sha256_prefix":"d14f8c3635563b4a","entry":"fgsm_attack","repo":"ginevracoal/robustBNNs","repo_kind":"official","path":"adversarialAttacks.py","file_url":"https://github.com/ginevracoal/robustBNNs/blob/HEAD/adversarialAttacks.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"d14f8c3635563b4a"}},{"code_sha256_prefix":"7a624cbf8581d631","entry":"softmax_difference","repo":"ginevracoal/robustBNNs","repo_kind":"official","path":"adversarialAttacks.py","file_url":"https://github.com/ginevracoal/robustBNNs/blob/HEAD/adversarialAttacks.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"7a624cbf8581d631"}},{"code_sha256_prefix":"035ebc80c422187f","entry":"softmax_robustness","repo":"ginevracoal/robustBNNs","repo_kind":"official","path":"adversarialAttacks.py","file_url":"https://github.com/ginevracoal/robustBNNs/blob/HEAD/adversarialAttacks.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"035ebc80c422187f"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}