Adversarial Attacks Leverage Interference Between Features in Superposition

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Stevinson, Edward, Prieto, Lucas, Barsbey, Melih, Birdal, Tolga
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918159691284480
author Stevinson, Edward
Prieto, Lucas
Barsbey, Melih
Birdal, Tolga
author_facet Stevinson, Edward
Prieto, Lucas
Barsbey, Melih
Birdal, Tolga
contents Fundamental questions remain about when and why adversarial examples arise in neural networks, with competing views characterising them either as artifacts of the irregularities in the decision landscape or as products of sensitivity to non-robust input features. In this paper, we instead argue that adversarial vulnerability can stem from efficient information encoding in neural networks. Specifically, we show how superposition - where networks represent more features than they have dimensions - creates arrangements of latent representations that adversaries can exploit. We demonstrate that adversarial perturbations leverage interference between superposed features, making attack patterns predictable from feature arrangements. Our framework provides a mechanistic explanation for two known phenomena: adversarial attack transferability between models with similar training regimes and class-specific vulnerability patterns. In synthetic settings with precisely controlled superposition, we establish that superposition suffices to create adversarial vulnerability. We then demonstrate that these findings persist in a ViT trained on CIFAR-10. These findings reveal adversarial vulnerability can be a byproduct of networks' representational compression, rather than flaws in the learning process or non-robust inputs.
format Preprint
id arxiv_https___arxiv_org_abs_2510_11709
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adversarial Attacks Leverage Interference Between Features in Superposition
Stevinson, Edward
Prieto, Lucas
Barsbey, Melih
Birdal, Tolga
Machine Learning
Artificial Intelligence
Computer Vision and Pattern Recognition
Fundamental questions remain about when and why adversarial examples arise in neural networks, with competing views characterising them either as artifacts of the irregularities in the decision landscape or as products of sensitivity to non-robust input features. In this paper, we instead argue that adversarial vulnerability can stem from efficient information encoding in neural networks. Specifically, we show how superposition - where networks represent more features than they have dimensions - creates arrangements of latent representations that adversaries can exploit. We demonstrate that adversarial perturbations leverage interference between superposed features, making attack patterns predictable from feature arrangements. Our framework provides a mechanistic explanation for two known phenomena: adversarial attack transferability between models with similar training regimes and class-specific vulnerability patterns. In synthetic settings with precisely controlled superposition, we establish that superposition suffices to create adversarial vulnerability. We then demonstrate that these findings persist in a ViT trained on CIFAR-10. These findings reveal adversarial vulnerability can be a byproduct of networks' representational compression, rather than flaws in the learning process or non-robust inputs.
title Adversarial Attacks Leverage Interference Between Features in Superposition
topic Machine Learning
Artificial Intelligence
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2510.11709