PAPER DIGEST
Most Influential ICLR 2019 Paper · 2026-03 edition

Robustness May Be at Odds with Accuracy

Dimitris Tsipras; Shibani Santurkar; Logan Engstrom; Alexander Turner; Aleksander Madry

Venue
International Conference on Learning Representations (ICLR) 2019
Recognition
Most Influential ICLR 2019 Paper (Rank No. 15)
Edition
2026-03
Impact factor
9
Certificate ID
f5ce6ac2a83ce29b

Abstract

We show that there exists an inherent tension between the goal of adversarial robustness and that of standard generalization.Specifically, training robust models may not only be more resource-consuming, but also lead to a reduction of standard accuracy. We demonstrate that this trade-off between the standard accuracy of a model and its robustness to adversarial perturbations provably exists even in a fairly simple and natural setting. These findings also corroborate a similar phenomenon observed in practice. Further, we argue that this phenomenon is a consequence of robust classifiers learning fundamentally different feature representations than standard classifiers. These differences, in particular, seem to result in unexpected benefits: the features learned by robust models tend to align better with salient data characteristics and human perception.

Download PDF certificate