Related Experiment Video
Updated: Aug 1, 2025

Author Spotlight: Efficient Image Recognition Using Directional Gradient Histogram Technique and Support Vector Machines
Published on: January 5, 2024
Quantifying the Preferential Direction of the Model Gradient in Adversarial Training With Projected Gradient Descent
Ricardo Bigolin Lanfredi1, Joyce D Schroeder2, Tolga Tasdizen1
1Scientific Computing and Imaging Institute, 72 S Central Campus Drive, Room 3750, Salt, Lake City, UT 84112, USA.
Projected gradient descent (PGD) enhances model robustness. A new metric quantifies gradient alignment, showing PGD models align better and improved alignment boosts robustness against adversarial attacks.
Area of Science:
- Machine Learning
- Computer Vision
- Artificial Intelligence Security
Background:
- Adversarial training, particularly Projected Gradient Descent (PGD), is effective for enhancing model robustness against adversarial attacks.
- Post-adversarial training, model gradients exhibit a preferential direction, but this alignment is not well-defined quantitatively.
Purpose of the Study:
- To introduce a novel mathematical definition for the preferential direction of model gradients after adversarial training.
- To develop and apply a metric for quantitatively evaluating this gradient alignment.
- To investigate the impact of enforcing this alignment on model robustness.
Main Methods:
- Defined the preferential gradient direction as the vector towards the closest support of the nearest incorrect class in decision space.
- Utilized generative adversarial networks (GANs) to create a metric measuring the minimal perturbation required to alter image classification.
- Evaluated gradient alignment in PGD-trained models versus baseline models.
Main Results:
- PGD-trained models demonstrated significantly higher gradient alignment compared to baseline models based on the proposed definition.
- The proposed GAN-based metric yielded higher alignment values than a competing metric.
- Explicitly enforcing the defined gradient alignment improved model robustness.
Conclusions:
- The novel definition and metric provide a quantitative measure for gradient alignment in adversarially trained models.
- The findings confirm that PGD training leads to better alignment and that enforcing this alignment enhances adversarial robustness.
Related Concept Videos
Gradient and Del Operator
What is an Electrochemical Gradient?
The chemical gradient relies on differences in the abundance of a substance on the outside versus the inside of a cell and flows from areas of high to low ion concentration. In contrast, the electrical gradient revolves around an...
Direction of Acceleration Vectors
Poisson's And Laplace's Equation
Position and Displacement Vectors
Further, several important kinds of...
Curvilinear Motion: Rectangular Components
As the car advances, its position evolves over time. Quantifying the car's velocity involves computing the...

