acceptodds
Under review as a conference paper at ICLR 2027

Understanding Adversarial Robustness through Semantic-Region Membership

Abstract

Adversarial robustness remains an important research topic for improving the reliability and security of deep neural networks. Conventional research on adversarial attacks and defences mainly evaluates robustness through prediction accuracy on clean images and their corresponding adversarial examples. In this paper, we define class-specific semantic regions based on the geometric organisation of learned feature representations and conduct experiments across a range of adversarially robust models and a model trained only on clean images. Our results reveal that adversarial robustness is not associated with stronger semantic organisation of clean representations, but rather with the preservation of semantic-region membership under adversarial perturbations. we derive a sufficient condition to establish the relationship between semantic-region membership preservation and adversarial feature displacement. We employ a feature-space PGD attack to empirically estimate adversarial feature displacement and evaluate the derived sufficient condition for semantic-region membership preservation. The results show that all feature representations of adversarial examples lie within their corresponding semantic region if they satisfy that condition. Another interesting finding is that even an adversarial example has been misclassified, its feature representation may still lie within its corresponding semantic region. These findings extends the robustness studies from conventional prediction-level to semantic organisation in learn feature space. feature representation may still lie within its corresponding semantic region. These findings extend robustness studies from the prediction level to semantic organisation in the learned feature space.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.