Understanding the Intrinsic Robustness of Image Distributions using Conditional Generative Models

Starting with Gilmer et al. (2018), several works have demonstrated the\ninevitability of adversarial examples based on different assumptions about the\nunderlying input probability space. It remains unclear, however, whether these\nresults apply to natural image distributions. In this work, we assume the\nunderlying data distribution is captured by some conditional generative model,\nand prove intrinsic robustness bounds for a general class of classifiers, which\nsolves an open problem in Fawzi et al. (2018). Building upon the\nstate-of-the-art conditional generative models, we study the intrinsic\nrobustness of two common image benchmarks under $\\ell_2$ perturbations, and\nshow the existence of a large gap between the robustness limits implied by our\ntheory and the adversarial robustness achieved by current state-of-the-art\nrobust models. Code for all our experiments is available at\nhttps://github.com/xiaozhanguva/Intrinsic-Rob.\n

Paper

References (37)

Scroll for more · 25 remaining

Similar papers

© 2026 NYSGPT2525 LLC