{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/wasserstein-distributional-robustness-of-1","title":"Wasserstein distributional robustness of neural networks","arxiv_id":"2306.09844","date":"2023-06-16","proceeding":"NeurIPS 2023 11","authors":["Xingjian Bai","Guangyi He","Yifan Jiang","Jan Obloj"],"abstract":"Deep neural networks are known to be vulnerable to adversarial attacks (AA). For an image recognition task, this means that a small perturbation of the original can result in the image being misclassified. Design of such attacks as well as methods of adversarial training against them are subject of intense research. We re-cast the problem using techniques of Wasserstein distributionally robust optimization (DRO) and obtain novel contributions leveraging recent insights from DRO sensitivity analysis. We consider a set of distributional threat models. Unlike the traditional pointwise attacks, which assume a uniform bound on perturbation of each input data point, distributional threat models allow attackers to perturb inputs in a non-uniform way. We link these more general attacks with questions of out-of-sample performance and Knightian uncertainty. To evaluate the distributional robustness of neural networks, we propose a first-order AA algorithm and its multi-step version. Our attack algorithms include Fast Gradient Sign Method (FGSM) and Projected Gradient Descent (PGD) as special cases. Furthermore, we provide a new asymptotic estimate of the adversarial accuracy against distributional threat models. The bound is fast to compute and first-order accurate, offering new insights even for the pointwise AA. It also naturally yields out-of-sample performance guarantees. We conduct numerical experiments on the CIFAR-10 dataset using DNNs on RobustBench to illustrate our theoretical results. Our code is available at https://github.com/JanObloj/W-DRO-Adversarial-Methods.","url_abs":"https://arxiv.org/abs/2306.09844v1","url_pdf":"https://arxiv.org/pdf/2306.09844v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"wasserstein-distributional-robustness-of-1","repo_url":"https://github.com/janobloj/w-dro-adversarial-methods","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2306.09844","atlas_url":"https://app.syntology.ai/?focus=2306.09844","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2306.09844"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/janobloj/w-dro-adversarial-methods","reach":{"status":"ok","spdx":"MIT"}}],"summary":{"ran_honours":1,"unverified":7},"by_repo_kind":{"official":{"samples":8,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"f321f54723433661","entry":"pil_loader","repo":"janobloj/w-dro-adversarial-methods","repo_kind":"official","path":"src/imagenet_loader.py","file_url":"https://github.com/janobloj/w-dro-adversarial-methods/blob/HEAD/src/imagenet_loader.py","link_basis":"harvester_set","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":"well_formed","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"f321f54723433661"}},{"code_sha256_prefix":"404fb2b2daa1ae78","entry":"accimage_loader","repo":"janobloj/w-dro-adversarial-methods","repo_kind":"official","path":"src/imagenet_loader.py","file_url":"https://github.com/janobloj/w-dro-adversarial-methods/blob/HEAD/src/imagenet_loader.py","link_basis":"harvester_set","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"404fb2b2daa1ae78"}},{"code_sha256_prefix":"644cf31925f95e57","entry":"dict_translate","repo":"janobloj/w-dro-adversarial-methods","repo_kind":"official","path":"src/utils.py","file_url":"https://github.com/janobloj/w-dro-adversarial-methods/blob/HEAD/src/utils.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"644cf31925f95e57"}},{"code_sha256_prefix":"ca6af5b893212974","entry":"get_cifar100_split","repo":"janobloj/w-dro-adversarial-methods","repo_kind":"official","path":"src/data.py","file_url":"https://github.com/janobloj/w-dro-adversarial-methods/blob/HEAD/src/data.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"ca6af5b893212974"}},{"code_sha256_prefix":"4045004ed37b8e13","entry":"get_cifar10_split","repo":"janobloj/w-dro-adversarial-methods","repo_kind":"official","path":"src/data.py","file_url":"https://github.com/janobloj/w-dro-adversarial-methods/blob/HEAD/src/data.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"4045004ed37b8e13"}},{"code_sha256_prefix":"de4f6c380abb5474","entry":"if_exist","repo":"janobloj/w-dro-adversarial-methods","repo_kind":"official","path":"src/utils.py","file_url":"https://github.com/janobloj/w-dro-adversarial-methods/blob/HEAD/src/utils.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"de4f6c380abb5474"}},{"code_sha256_prefix":"c4c57c3f5b63ae66","entry":"make_custom_dataset","repo":"janobloj/w-dro-adversarial-methods","repo_kind":"official","path":"src/imagenet_loader.py","file_url":"https://github.com/janobloj/w-dro-adversarial-methods/blob/HEAD/src/imagenet_loader.py","link_basis":"plan_row","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"c4c57c3f5b63ae66"}},{"code_sha256_prefix":"cc73e4fb2da3b7d3","entry":"sizing","repo":"janobloj/w-dro-adversarial-methods","repo_kind":"official","path":"src/utils.py","file_url":"https://github.com/janobloj/w-dro-adversarial-methods/blob/HEAD/src/utils.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"cc73e4fb2da3b7d3"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}