MATH · IN · MODELS

Standard classifiers have higher decision-boundary curvature than robust ones

measured in 1 paper

- Estimating decision-boundary curvature via a dynamic-curvature trajectory (built into a black-box attack, CDBA on CGBA) shows standard non-robust classifiers consistently have higher curvature than robust ones (log-curvature WideResNet-28-10 standard -0.63 vs l2-robust -3.32; ResNet-50 standard 3.24 vs l-inf-robust 0.17). [sun-2025-curvature-dynamic-black-box-attack] - The curvature-robustness link is a qualitative/ordinal ordering only: the paper reports no correlation coefficient, p-value, or hypothesis test for curvature vs robustness (its only ANOVA, F=4.88, p=0.002, concerns the number of initial queries). [sun-2025-curvature-dynamic-black-box-attack] - Evaluated on RobustBench standard and robust variants: WideResNet-28-10 (CIFAR-10), ResNet-101 (CIFAR-10, randomized-smoothing certified) and ResNet-50 (ImageNet). [sun-2025-curvature-dynamic-black-box-attack] - Observational/comparative; no causal intervention. [sun-2025-curvature-dynamic-black-box-attack]

Context

adversarial-robustness, decision-boundary-curvature

Papers

Curvature Dynamic Black-box Attack: Revisiting Adversarial Robustness via Dynamic Curvature Estimation — Sun, Peiran2025 · arXiv:2505.19194