acceptodds
Under review as a conference paper at ICLR 2027

Rank Trajectories for Adversarial Robustness via Quantized Tensor Train

Abstract

Many defenses against adversarial examples rely on an explicit or implicit model of the natural-image distribution and are evaluated primarily by reconstruction quality. We pursue a different question: whether the multiscale tensor structure of an image provides an interpretable and computable basis for analyzing adversarial robustness. We study this question through quantized tensor-train (QTT) representations, whose modes encode spatial scales and whose bond ranks measure their interactions. Tensors satisfying nontrivial QTT-rank constraints form lower-dimensional algebraic sets, and natural images empirically concentrate near this low-rank structure. An adversarial perturbation, in contrast, comes from a search constrained only by a norm budget and a misclassification objective, and neither constraint confines it to these sets. To connect this geometry to model behavior, we introduce rank trajectories, which track predictions along progressively higher-rank reconstructions from a single decomposition sweep. Clean examples typically stabilize at moderate ranks, whereas adversarial examples often emerge later. The same geometry also has a constructive use inside randomized smoothing. A training-free filter suppresses the weak singular directions that carry most of the Gaussian smoothing noise. Experiments show that it consistently improves certified accuracy over plain smoothing in the high-noise regime. Together, these results establish QTT rank as a multiscale coordinate for analyzing adversarial robustness, and improves certified robustness under strong smoothing noise.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.