Aug 2026· International Symposium on Low Power Electronics and Design· pp. 1-7· 0 citations· 22 references
Computer Science
TL;DR
Across CIFAR10, COIL100, and ETH80 under FGSM and Genetic Attack, ViT + Classical HDC degrades more gracefully than Pure HDC and ViT + HDC baselines, and achieves higher normalized AURC, lower attack-time decision margins, and larger gains from partial adversarial retraining.
Abstract
Neuro-symbolic models may improve robustness by combining learned representations with structured composition, but their behavior under adversarial perturbation remains underexplored. We study a hybrid pipeline that fuses ViT features with classical descriptors through Hyperdimensional Computing (HDC). Across CIFAR10 (Subset), COIL100, and ETH80 under FGSM and Genetic Attack, ViT + Classical HDC degrades more gracefully than Pure HDC and ViT + HDC baselines. It achieves higher normalized AURC, lower attack-time decision margins, and larger gains from partial adversarial retraining. These results suggest that classical-neural fusion within HDC is a promising direction for robustness under the evaluated threat models.
VisionDES is introduced, a novel DES framework for image classification that uses deep model embeddings to estimate classifier competence and consistently outperforms static ensembles and existing uncertainty-based DES methods, improving robust accuracy under strong attacks and under distribution shifts.
Firuz Juraev, Mohammad Abuhamad, Shaker El-Sappagh et al.· Proceedings of the 32nd ACM...· 0 citations
Machine learning models remain highly susceptible to adversarial perturbations, which can cause them to produce incorrect predictions while remaining imperceptible to humans. Existing defense methods usually emphasize either detection or robust training in isolation, which limits their capability to deal with adaptive...
B. Durga, Adike Sri Vathsankitha, Aechikuchi Sathwika et al.· 2026 International Conferenc...· 0 citations
Recurrent reasoning models (RRMs) can solve structured problems, achieving easy-to-hard generalization through iterative computation in hidden space. These models are typically trained with instance-level supervision, which becomes increasingly problematic as task difficulty grows: valid solutions occupy a tiny region...
Adversarial robustness in computer vision is still largely achieved through adversarial training or test-time adversarial purification, both of which introduce significant computational overhead by generating adversarial examples during training or performing iterative denoising at test time. We study whether empirical...
M. Habibi, Klea Ziu, Martin Takác et al.· 0 citations
This work establishes a high-probability generalization bound for ViTs in classification tasks under adversarial settings, and elucidates the roles of several factors in mitigating perturbation effects, norm regularization of weight matrices and depth-wise propagation constraints on layer-wise norms.
Zi-Wen Jiang, Chang Cao, Han Li et al.· Proceedings of the Thirty-Fi...· 0 citations
In order to make Reinforcement Learning algorithms applicable in real world scenarios, safety must be ensured even under adverse operating conditions. In this work, we consider the challenge of adversarial feature missingness: a scenario in which an adversary occludes features from the agent's observation in order to r...
Paul Stahlhofen, Luca Hermes, Tim Kochs et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.