S2AP: Score-space Sharpness Minimization for Adversarial Pruning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Piras, Giorgio, Zhao, Qi, Brau, Fabio, Pintor, Maura, Wressnegger, Christian, Biggio, Battista
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918164728643584
author Piras, Giorgio
Zhao, Qi
Brau, Fabio
Pintor, Maura
Wressnegger, Christian
Biggio, Battista
author_facet Piras, Giorgio
Zhao, Qi
Brau, Fabio
Pintor, Maura
Wressnegger, Christian
Biggio, Battista
contents Adversarial pruning methods have emerged as a powerful tool for compressing neural networks while preserving robustness against adversarial attacks. These methods typically follow a three-step pipeline: (i) pretrain a robust model, (ii) select a binary mask for weight pruning, and (iii) finetune the pruned model. To select the binary mask, these methods minimize a robust loss by assigning an importance score to each weight, and then keep the weights with the highest scores. However, this score-space optimization can lead to sharp local minima in the robust loss landscape and, in turn, to an unstable mask selection, reducing the robustness of adversarial pruning methods. To overcome this issue, we propose a novel plug-in method for adversarial pruning, termed Score-space Sharpness-aware Adversarial Pruning (S2AP). Through our method, we introduce the concept of score-space sharpness minimization, which operates during the mask search by perturbing importance scores and minimizing the corresponding robust loss. Extensive experiments across various datasets, models, and sparsity levels demonstrate that S2AP effectively minimizes sharpness in score space, stabilizing the mask selection, and ultimately improving the robustness of adversarial pruning methods.
format Preprint
id arxiv_https___arxiv_org_abs_2510_18381
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle S2AP: Score-space Sharpness Minimization for Adversarial Pruning
Piras, Giorgio
Zhao, Qi
Brau, Fabio
Pintor, Maura
Wressnegger, Christian
Biggio, Battista
Computer Vision and Pattern Recognition
Artificial Intelligence
Machine Learning
Adversarial pruning methods have emerged as a powerful tool for compressing neural networks while preserving robustness against adversarial attacks. These methods typically follow a three-step pipeline: (i) pretrain a robust model, (ii) select a binary mask for weight pruning, and (iii) finetune the pruned model. To select the binary mask, these methods minimize a robust loss by assigning an importance score to each weight, and then keep the weights with the highest scores. However, this score-space optimization can lead to sharp local minima in the robust loss landscape and, in turn, to an unstable mask selection, reducing the robustness of adversarial pruning methods. To overcome this issue, we propose a novel plug-in method for adversarial pruning, termed Score-space Sharpness-aware Adversarial Pruning (S2AP). Through our method, we introduce the concept of score-space sharpness minimization, which operates during the mask search by perturbing importance scores and minimizing the corresponding robust loss. Extensive experiments across various datasets, models, and sparsity levels demonstrate that S2AP effectively minimizes sharpness in score space, stabilizing the mask selection, and ultimately improving the robustness of adversarial pruning methods.
title S2AP: Score-space Sharpness Minimization for Adversarial Pruning
topic Computer Vision and Pattern Recognition
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2510.18381