Browse State-of-the-Art › Adversarial Robustness
Adversarial Robustness
788 papers with code · 7 benchmarks · 13 datasets archive 2025-07-28
Adversarial Robustness evaluates the vulnerabilities of machine learning models under various types of adversarial attacks.
Description from the archive archive 2025-07-28.
Benchmarks archive 2025-07-28
7 leaderboard tables shown for this task, 7 with rows (a “benchmark” on this site is a table with at least one row, as on /sota), ordered by row count. “Best model” is the first row in the archive's own order at snapshot; nothing is re-ranked here and metric direction is not recorded in the archive. PwC's Trend sparklines are not in the archive, so that column is omitted.
| Dataset | Best model (first row in archive order) | Paper | Code | Syntology | Compare |
|---|---|---|---|---|---|
| AdvGLUE (10 rows) | DeBERTa (single model) | Adversarial GLUE: A Multi-Task Benchmark for Robustness Evaluation... | code | — | Compare |
| CIFAR-10 (5 rows) | Mixed classifier | Improving the Accuracy-Robustness Trade-Off of Classifiers via... | code | Syntology ran 0 of 8 samples · 8 unverified | Compare |
| ImageNet (4 rows) | ResNet-50 (SGD, Cosine) | Are Transformers More Robust Than CNNs? | code | — | Compare |
| ImageNet-A (4 rows) | DeiT-S (AdamW, Cosine) | Are Transformers More Robust Than CNNs? | code | — | Compare |
| ImageNet-C (4 rows) | DeiT-S (AdamW, Cosine) | Are Transformers More Robust Than CNNs? | code | — | Compare |
| Stylized ImageNet (4 rows) | DeiT-S (AdamW, Cosine) | Are Transformers More Robust Than CNNs? | code | — | Compare |
| CIFAR-100 (2 rows) | Mixed Classifier | Improving the Accuracy-Robustness Trade-Off of Classifiers via... | code | Syntology ran 0 of 8 samples · 8 unverified | Compare |
Syntology column: samples harvested from the paper's repositories and executed on synthesized fixtures; “ran” is not a correctness claim and does not order the table. A dash means no Syntology record for that paper, not a recorded non-run. Read from the graph 2026-09-24.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
13 datasets whose archive record lists this task, ordered by the archive's paper count.
Subtasks archive 2025-07-28
No subtask under this task in the archive's task tree.
Most implemented papers archive 2025-07-28
30 shown of 788 papers with code (1,746 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
19 Jun 2017 59 repositories listed Syntology ran 9 of 17 samples · 8 unverified · 13 pointer-only (licence)Its principled nature also enables us to identify methods for both training and attacking neural networks that are reliable and, in a certain sense, universal.
-
8 Feb 2019 12 repositories listedWe show how to turn any classifier that classifies well under Gaussian noise into a new classifier that is certifiably robust to adversarial perturbations under the ℓ₂ norm.
-
8 Jan 2018 10 repositories listedA challenge to explore adversarial robustness of neural networks on MNIST.
-
24 Jan 2019 9 repositories listed Syntology ran 12 of 15 samples · 3 unverified · 4 pointer-only (licence)We identify a trade-off between robustness and accuracy that serves as a guiding principle in the design of defenses against adversarial examples.
-
3 Mar 2020 8 repositories listed Syntology ran 3 of 5 samples · 2 unverified · 4 pointer-only (licence)The field of defense strategies against adversarial attacks has significantly grown over the last years, but progress is hampered as the evaluation of adversarial defenses is often insufficient and thus gives a wrong…
-
30 May 2018 8 repositories listedWe show that there may exist an inherent tension between the goal of adversarial robustness and that of standard generalization.
-
2 Mar 2021 7 repositories listedIn particular, against ℓ_∞ norm-bounded perturbations of size ϵ= 8/255, our model reaches 64.
-
3 Jul 2018 7 repositories listedDefending Machine Learning models involves certifying and verifying model robustness and model hardening with approaches such as pre-processing inputs, augmenting training data with adversarial samples, and leveraging…
-
25 Jan 2019 6 repositories listed Syntology ran 2 of 2 samples · 0 unverifiedThough deep neural networks have achieved significant progress on various tasks, often enhanced by model ensemble, existing high-performance models can be vulnerable to adversarial attacks.
-
13 Sep 2017 6 repositories listed Syntology ran 0 of 1 samples · 1 unverified · 1 pointer-only (licence)Recent studies have highlighted the vulnerability of deep neural networks (DNNs) to adversarial examples - a visually indistinguishable adversarial image can easily be crafted to cause a well-trained model to…
-
2 Feb 2023 5 repositories listed Syntology ran 0 of 6 samples · 6 unverified · 6 pointer-only (licence)Most work on the formal verification of neural networks has focused on bounding the set of outputs that correspond to a given set of inputs (for example, bounded perturbations of a nominal input).
-
3 Jun 2019 5 repositories listedIn this work, we show that robust optimization can be re-cast as a tool for enforcing priors on the features learned by deep neural networks.
-
6 Jun 2024 4 repositories listed Syntology ran 3 of 6 samples · 3 unverified · 1 pointer-only (licence)Existing techniques aimed at improving alignment, such as refusal training, are often bypassed.
-
23 May 2023 4 repositories listed Syntology ran 7 of 11 samples · 4 unverified · 4 pointer-only (licence)In this paper, we delve deeper into the Kullback-Leibler (KL) Divergence loss and mathematically prove that it is equivalent to the Decoupled Kullback-Leibler (DKL) Divergence loss that consists of 1) a weighted Mean…
-
13 Oct 2022 4 repositories listed Syntology ran 2 of 2 samples · 0 unverified · 2 pointer-only (licence)As a new paradigm in machine learning, self-supervised learning (SSL) is capable of learning high-quality representations of complex data without relying on labels.
-
7 Oct 2020 4 repositories listedIn the setting with additional unlabeled data, we obtain an accuracy under attack of 65.
-
31 May 2019 4 repositories listed Syntology ran 1 of 8 samples · 7 unverifiedWe demonstrate, theoretically and empirically, that adversarial robustness can significantly benefit from semisupervised learning.
-
18 Feb 2019 4 repositories listedCorrectly evaluating defenses against adversarial examples has proven to be extremely difficult.
-
2 Feb 2024 3 repositories listed Syntology ran 10 of 15 samples · 5 unverified · 13 pointer-only (licence)Evaluating the adversarial robustness of deep networks to gradient-based attacks is challenging.
-
24 May 2023 3 repositories listed Syntology ran 0 of 3 samples · 3 unverified · 3 pointer-only (licence)As RDC does not require training on particular adversarial attacks, we demonstrate that it is more generalizable to defend against multiple unseen threats.
-
21 Jun 2022 3 repositories listed Syntology ran 14 of 34 samples · 20 unverifiedIn this paper we show how to achieve state-of-the-art certified adversarial robustness to 2-norm bounded perturbations by relying exclusively on off-the-shelf pretrained models.
-
4 May 2022 3 repositories listed Syntology ran 2 of 4 samples · 2 unverified · 2 pointer-only (licence)Standard federated optimization methods successfully apply to stochastic problems with single-level structure.
-
3 Jun 2021 3 repositories listed Syntology ran 2 of 3 samples · 1 unverified · 1 pointer-only (licence)In this work, we introduce a fast, general and accurate adversarial attack that optimises the original non-convex constrained minimisation problem.
-
25 Feb 2021 3 repositories listed Syntology ran 2 of 2 samples · 0 unverifiedEvaluating adversarial robustness amounts to finding the minimum perturbation needed to have an input sample misclassified.
-
30 Apr 2020 3 repositories listed Syntology ran 1 of 2 samples · 1 unverifiedIn this work, we propose to employ mode connectivity in loss landscapes to study the adversarial robustness of deep neural networks, and provide novel methods for improving this robustness.
-
13 Apr 2020 3 repositories listed Syntology ran 2 of 5 samples · 3 unverifiedThe study on improving the robustness of deep neural networks against adversarial examples grows rapidly in recent years.
-
21 Aug 2019 3 repositories listed Syntology ran 3 of 18 samples · 15 unverified · 3 pointer-only (licence)To narrow in on this discrepancy between research and reality we introduce ImageNet-UA, a framework for evaluating model robustness against a range of unforeseen adversaries, including eighteen new non-L_p attacks.
-
16 Jun 2019 3 repositories listed Syntology ran 2 of 2 samples · 0 unverified · 2 pointer-only (licence)Adversarial robustness has become a central goal in deep learning, both in the theory and the practice.
-
20 Feb 2019 3 repositories listed Syntology ran 0 of 1 samples · 1 unverified · 1 pointer-only (licence)advertorch is a toolbox for adversarial robustness research.
-
10 Sep 2018 3 repositories listed Syntology ran 0 of 9 samples · 9 unverifiedThe existence of adversarial data examples has drawn significant attention in the deep-learning community; such data are seemingly minimally perturbed relative to the original data, but lead to very different outputs…
Syntology lines on 22 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections