Drawing Robust Scratch Tickets: Subnetworks with Inborn Robustness Are Found within Randomly Initialized Networks

Deep Neural Networks (DNNs) are known to be vulnerable to adversarial\nattacks, i.e., an imperceptible perturbation to the input can mislead DNNs\ntrained on clean images into making erroneous predictions. To tackle this,\nadversarial training is currently the most effective defense method, by\naugmenting the training set with adversarial samples generated on the fly.\nInterestingly, we discover for the first time that there exist subnetworks with\ninborn robustness, matching or surpassing the robust accuracy of the\nadversarially trained networks with comparable model sizes, within randomly\ninitialized networks without any model training, indicating that adversarial\ntraining on model weights is not indispensable towards adversarial robustness.\nWe name such subnetworks Robust Scratch Tickets (RSTs), which are also by\nnature efficient. Distinct from the popular lottery ticket hypothesis, neither\nthe original dense networks nor the identified RSTs need to be trained. To\nvalidate and understand this fascinating finding, we further conduct extensive\nexperiments to study the existence and properties of RSTs under different\nmodels, datasets, sparsity patterns, and attacks, drawing insights regarding\nthe relationship between DNNs' robustness and their\ninitialization/overparameterization. Furthermore, we identify the poor\nadversarial transferability between RSTs of different sparsity ratios drawn\nfrom the same randomly initialized dense network, and propose a Random RST\nSwitch (R2S) technique, which randomly switches between different RSTs, as a\nnovel defense method built on top of RSTs. We believe our findings about RSTs\nhave opened up a new perspective to study model robustness and extend the\nlottery ticket hypothesis.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC