Improving Adversarial Robustness of Attribution via Implicit Regularization

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Mehrpanah, Amir, Gamba, Matteo, Azizpour, Hossein
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917543947534336
author Mehrpanah, Amir
Gamba, Matteo
Azizpour, Hossein
author_facet Mehrpanah, Amir
Gamba, Matteo
Azizpour, Hossein
contents The adversarial robustness of attributions is a fundamental requirement for reliable explainability in deep learning, yet existing approaches typically rely on computationally expensive explicit regularization. In this work, we show that attribution robustness can arise implicitly from the learning dynamics of standard stochastic gradient descent. We theoretically motivate this effect through connections between parameter-space and input-space curvature, and validate it across architectures, datasets, and attribution methods, with negligible computational overhead. In contrast, we prove that such robustness gains often does not transfer to attention-based attribution under softmax normalization, due to inherent entropy constraints, and we validate this limitation experimentally. Finally, we show that replacing softmax attention with kernel-based attention restores the robustness gains in transformer models. Our results highlight learning dynamics as a principled and practical mechanism for robust explainability, and reveal fundamental limitations of attention-based attribution under normalization.
format Preprint
id arxiv_https___arxiv_org_abs_2605_29983
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Improving Adversarial Robustness of Attribution via Implicit Regularization
Mehrpanah, Amir
Gamba, Matteo
Azizpour, Hossein
Machine Learning
Computer Vision and Pattern Recognition
The adversarial robustness of attributions is a fundamental requirement for reliable explainability in deep learning, yet existing approaches typically rely on computationally expensive explicit regularization. In this work, we show that attribution robustness can arise implicitly from the learning dynamics of standard stochastic gradient descent. We theoretically motivate this effect through connections between parameter-space and input-space curvature, and validate it across architectures, datasets, and attribution methods, with negligible computational overhead. In contrast, we prove that such robustness gains often does not transfer to attention-based attribution under softmax normalization, due to inherent entropy constraints, and we validate this limitation experimentally. Finally, we show that replacing softmax attention with kernel-based attention restores the robustness gains in transformer models. Our results highlight learning dynamics as a principled and practical mechanism for robust explainability, and reveal fundamental limitations of attention-based attribution under normalization.
title Improving Adversarial Robustness of Attribution via Implicit Regularization
topic Machine Learning
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2605.29983