A Geometric Probe of the Accuracy-Robustness Trade-off: Sharp Boundaries in Symmetry-Breaking Dimensional Expansion

📅 2026-02-20
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work investigates the geometric origins of the trade-off between clean accuracy and adversarial robustness in deep learning. By introducing Symmetry-Breaking Dimension Expansion (SBDE)—a method that appends constant-valued pixels to inputs to boost accuracy—and combining it with test-time mask projection to analyze robustness effects, the study provides a clear geometric interpretation of this trade-off. For the first time, SBDE is employed as a controllable geometric probe, revealing that accuracy gains arise from the formation of sharp decision boundaries and steep loss gradients along auxiliary dimensions. Experiments on CIFAR-10 demonstrate that ResNet-18’s clean accuracy improves from 90.47% to 95.63%, while mask projection nearly fully restores adversarial robustness, confirming that the induced vulnerability indeed stems from the inserted dimensions.

Technology Category

Application Category

📝 Abstract
The trade-off between clean accuracy and adversarial robustness is a pervasive phenomenon in deep learning, yet its geometric origin remains elusive. In this work, we utilize Symmetry-Breaking Dimensional Expansion (SBDE) as a controlled probe to investigate the mechanism underlying this trade-off. SBDE expands input images by inserting constant-valued pixels, which breaks translational symmetry and consistently improves clean accuracy (e.g., from $90.47\%$ to $95.63\%$ on CIFAR-10 with ResNet-18) by reducing parameter degeneracy. However, this accuracy gain comes at the cost of reduced robustness against iterative white-box attacks. By employing a test-time \emph{mask projection} that resets the inserted auxiliary pixels to their training values, we demonstrate that the vulnerability stems almost entirely from the inserted dimensions. The projection effectively neutralizes the attacks and restores robustness, revealing that the model achieves high accuracy by creating \emph{sharp boundaries} (steep loss gradients) specifically along the auxiliary axes. Our findings provide a concrete geometric explanation for the accuracy-robustness paradox: the optimization landscape deepens the basin of attraction to improve accuracy but inevitably erects steep walls along the auxiliary degrees of freedom, creating a fragile sensitivity to off-manifold perturbations.
Problem

Research questions and friction points this paper is trying to address.

accuracy-robustness trade-off
geometric origin
adversarial robustness
deep learning
symmetry-breaking
Innovation

Methods, ideas, or system contributions that make the work stand out.

Symmetry-Breaking Dimensional Expansion
accuracy-robustness trade-off
sharp boundaries
mask projection
geometric probe
🔎 Similar Papers
No similar papers found.
Y
Yu Bai
Northwest Institute of Nuclear Technology, Xi’an, 710024, P.R. China
Z
Zhe Wang
Northwest Institute of Nuclear Technology, Xi’an, 710024, P.R. China
J
Jiarui Zhang
Northwest Institute of Nuclear Technology, Xi’an, 710024, P.R. China
D
Dong-Xiao Zhang
Northwest Institute of Nuclear Technology, Xi’an, 710024, P.R. China
Y
Yinjun Gao
Northwest Institute of Nuclear Technology, Xi’an, 710024, P.R. China
J
Jun-Jie Zhang
Northwest Institute of Nuclear Technology, Xi’an, 710024, P.R. China