Related Experiment Video
Updated: Jun 28, 2025

11:18
Closed-loop Neuro-robotic Experiments to Test Computational Properties of Neuronal Networks
Published on: March 2, 2015
10.3K
On the Robustness of Bayesian Neural Networks to Adversarial Attacks
IEEE Transactions on Neural Networks and Learning Systems
|April 22, 2024
Summary
Bayesian neural networks (BNNs) show robustness to adversarial attacks in the over-parameterized limit. This is due to data distribution geometry, making BNN posteriors resistant to gradient-based attacks.
Area of Science:
- Machine Learning
- Deep Learning
- Artificial Intelligence Security
Background:
- Deep learning adoption in safety-critical applications is hindered by vulnerability to adversarial attacks.
- Current methods struggle to train robust deep learning models against these threats.
- Understanding the geometric properties of adversarial attacks is crucial.
Purpose of the Study:
- To analyze the geometry of adversarial attacks in the over-parameterized limit for Bayesian neural networks (BNNs).
- To demonstrate the inherent robustness of BNN posteriors to gradient-based adversarial attacks.
- To theoretically and empirically validate BNNs' resilience against various attack types.
Main Methods:
- Analysis of adversarial attack geometry in the over-parameterized limit for BNNs.
- Leveraging the convergence of infinitely-wide BNNs to Gaussian processes (GPs).
- Theoretical proof of vanishing expected loss gradient with respect to BNN posterior distribution.
- Experimental validation using Hamiltonian Monte Carlo and variational inference on benchmark datasets.
Main Results:
- Adversarial attack vulnerability in the limit stems from data distribution degeneracy (lower-dimensional submanifolds).
- BNN posteriors are robust to gradient-based adversarial attacks in the over-parameterized limit.
- Expected loss gradient vanishes for BNN posteriors, even if individual networks do not.
- Empirical evidence shows BNNs maintain high accuracy and robustness to gradient-based and gradient-free attacks.
Conclusions:
- The geometric properties of data distributions in the over-parameterized limit explain BNN robustness.
- BNNs offer a promising solution for developing deep learning models resilient to adversarial attacks.
- BNNs demonstrate potential for safe deployment in safety-critical AI applications.
Related Concept Videos
Neural Regulation
39.4K
Digestion begins with a cephalic phase that prepares the digestive system to receive food. When our brain processes visual or olfactory information about food, it triggers impulses in the cranial nerves innervating the salivary glands and stomach to prepare for food.
39.4K
Neuroplasticity
341
Neuroplasticity reflects the brain's remarkable capacity to adapt and evolve, responding dynamically to learning, experiences, or injury by reorganizing its neural circuitry. This reorganization involves creating new neural connections and refining old ones through a series of biological processes that contribute to the brain's lifelong development and adaptability.
341
The Blood-brain Barrier
47.3K
Overview
47.3K

