{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/towards-out-of-distribution-adversarial","title":"Towards Out-of-Distribution Adversarial Robustness","arxiv_id":"2210.03150","date":"2022-10-06","proceeding":null,"authors":["Adam Ibrahim","Charles Guille-Escuret","Ioannis Mitliagkas","Irina Rish","David Krueger","Pouya Bashivan"],"abstract":"Adversarial robustness continues to be a major challenge for deep learning. A core issue is that robustness to one type of attack often fails to transfer to other attacks. While prior work establishes a theoretical trade-off in robustness against different $L_p$ norms, we show that there is potential for improvement against many commonly used attacks by adopting a domain generalisation approach. Concretely, we treat each type of attack as a domain, and apply the Risk Extrapolation method (REx), which promotes similar levels of robustness against all training attacks. Compared to existing methods, we obtain similar or superior worst-case adversarial robustness on attacks seen during training. Moreover, we achieve superior performance on families or tunings of attacks only encountered at test time. On ensembles of attacks, our approach improves the accuracy from 3.4% with the best existing baseline to 25.9% on MNIST, and from 16.9% to 23.5% on CIFAR10.","url_abs":"https://arxiv.org/abs/2210.03150v4","url_pdf":"https://arxiv.org/pdf/2210.03150v4.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"towards-out-of-distribution-adversarial","repo_url":"https://github.com/aiproj/towards-out-of-distribution-adversarial-robustness","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[{"task_slug":"adversarial-robustness","task_name":"Adversarial Robustness"}],"methods":[{"method_slug":"test","method_name":"Test"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2210.03150","atlas_url":"https://app.syntology.ai/?focus=2210.03150","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2210.03150"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"deterministic:regex_extraction","url":"https://github.com/kuangliu/pytorch-cifar","reach":{"status":"ok","spdx":"MIT"}},{"provenance":"deterministic:regex_extraction","url":"https://github.com/AIproj/Towards-Out-of-Distribution-Adversarial-Robustness","reach":{"status":"ok"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/aiproj/towards-out-of-distribution-adversarial-robustness","reach":{"status":"ok"}}],"summary":{"ran_violates":1,"ran_fixture":1,"ran_draft_wrong":1},"by_repo_kind":{"official":{"samples":3,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":3,"samples":[{"code_sha256_prefix":"bf391ff4692ee518","entry":"REx_loss","repo":"AIproj/Towards-Out-of-Distribution-Adversarial-Robustness","repo_kind":"official","path":"experiments/MNIST/MLP/final/pretrain_MSD/REx_waterfall_lr_init_0.01beta4_early/MNIST_REx_pretrained_MSD.py","file_url":"https://github.com/AIproj/Towards-Out-of-Distribution-Adversarial-Robustness/blob/HEAD/experiments/MNIST/MLP/final/pretrain_MSD/REx_waterfall_lr_init_0.01beta4_early/MNIST_REx_pretrained_MSD.py","link_basis":"first_harvest_node","language":"python","status":"ran_violates","verification_level":1,"contract_check":"VIOLATES","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"bf391ff4692ee518"}},{"code_sha256_prefix":"a99591e938dd780e","entry":"compute_loss","repo":"AIproj/Towards-Out-of-Distribution-Adversarial-Robustness","repo_kind":"official","path":"experiments/MNIST/MLP/final/pretrain_MSD/REx_waterfall_lr_init_0.01beta4_early/MNIST_REx_pretrained_MSD.py","file_url":"https://github.com/AIproj/Towards-Out-of-Distribution-Adversarial-Robustness/blob/HEAD/experiments/MNIST/MLP/final/pretrain_MSD/REx_waterfall_lr_init_0.01beta4_early/MNIST_REx_pretrained_MSD.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"a99591e938dd780e"}},{"code_sha256_prefix":"7b592bf453e9b916","entry":"loss_helper","repo":"AIproj/Towards-Out-of-Distribution-Adversarial-Robustness","repo_kind":"official","path":"experiments/MNIST/MLP/final/pretrain_MSD/REx_waterfall_lr_init_0.01beta4_early/MNIST_REx_pretrained_MSD.py","file_url":"https://github.com/AIproj/Towards-Out-of-Distribution-Adversarial-Robustness/blob/HEAD/experiments/MNIST/MLP/final/pretrain_MSD/REx_waterfall_lr_init_0.01beta4_early/MNIST_REx_pretrained_MSD.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"7b592bf453e9b916"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}