Adversarial Training from Mean Field Perspective

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kumano, Soichiro, Kera, Hiroshi, Yamasaki, Toshihiko
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908371426213888
author Kumano, Soichiro
Kera, Hiroshi
Yamasaki, Toshihiko
author_facet Kumano, Soichiro
Kera, Hiroshi
Yamasaki, Toshihiko
contents Although adversarial training is known to be effective against adversarial examples, training dynamics are not well understood. In this study, we present the first theoretical analysis of adversarial training in random deep neural networks without any assumptions on data distributions. We introduce a new theoretical framework based on mean field theory, which addresses the limitations of existing mean field-based approaches. Based on this framework, we derive (empirically tight) upper bounds of $\ell_q$ norm-based adversarial loss with $\ell_p$ norm-based adversarial examples for various values of $p$ and $q$. Moreover, we prove that networks without shortcuts are generally not adversarially trainable and that adversarial training reduces network capacity. We also show that network width alleviates these issues. Furthermore, we present the various impacts of the input and output dimensions on the upper bounds and time evolution of the weight variance.
format Preprint
id arxiv_https___arxiv_org_abs_2505_14021
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adversarial Training from Mean Field Perspective
Kumano, Soichiro
Kera, Hiroshi
Yamasaki, Toshihiko
Machine Learning
Computer Vision and Pattern Recognition
Although adversarial training is known to be effective against adversarial examples, training dynamics are not well understood. In this study, we present the first theoretical analysis of adversarial training in random deep neural networks without any assumptions on data distributions. We introduce a new theoretical framework based on mean field theory, which addresses the limitations of existing mean field-based approaches. Based on this framework, we derive (empirically tight) upper bounds of $\ell_q$ norm-based adversarial loss with $\ell_p$ norm-based adversarial examples for various values of $p$ and $q$. Moreover, we prove that networks without shortcuts are generally not adversarially trainable and that adversarial training reduces network capacity. We also show that network width alleviates these issues. Furthermore, we present the various impacts of the input and output dimensions on the upper bounds and time evolution of the weight variance.
title Adversarial Training from Mean Field Perspective
topic Machine Learning
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2505.14021