acceptodds
Under review as a conference paper at ICLR 2027

Expected Adversarial Risk: A Data-Centric View of Adversarial Purification

Abstract

Adversarial purification has emerged as a promising defense strategy to mitigate adversarial attacks. Despite its effectiveness, the underlying mechanism remains unclear, making researchers resort to empirical algorithms rather than principled ones. In this paper, we propose a probabilistic, data-centric view of adversarial purification through the lens of Expected Adversarial Risk (EAR), which measures the probability that an example is assigned a wrong label across randomly sampled empirical datasets. We provide theoretical analysis for the effectiveness of adversarial purification, and attribute its success to alignment of purification directions with negative gradients of EAR. We further show that such alignment may not hold when severe class overlap or imbalance exist locally. Accordingly, we construct an EAR-inspired objective for purification, and demonstrate its effectiveness through experiments on synthetic and image datasets.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.