PapersWithELO
← ICLR 2024 leaderboard

Robust NAS under adversarial training: benchmark, theory, and beyond

Yongtao Wu, Fanghui Liu, Carl-Johann Simon-Gabriel, Grigorios Chrysos, Volkan Cevher

datasets & benchmarksneural architecture searchrobustnessbenchmarkgeneralization theory
73.10100
Fused
band ≈ ±15 pct pts (from σ = 0.30)
75.50100
Mimo
band ≈ ±22 pct pts (from σ = 0.43)
68.70100
DeepSeek
band ≈ ±21 pct pts (from σ = 0.41)

OpenReview ground truth

Accepted

TL;DR — To facilitate the neural architecture search for robust architecture, we release a benchmark under adversarial training and study the robust generalization theory

Abstract

Recent developments in neural architecture search (NAS) emphasize the significance of considering robust architectures against malicious data. However, there is a notable absence of benchmark evaluations and theoretical guarantees for searching these robust architectures, especially when adversarial training is considered. In this work, we aim to address these two challenges, making twofold contributions. First, we release a comprehensive data set that encompasses both clean accuracy and robust accuracy for a vast array of adversarially trained networks from the NAS-Bench-201 search space on image datasets. Then, leveraging the neural tangent kernel (NTK) tool from deep learning theory, we establish a generalization theory for searching architecture in terms of clean accuracy and robust accuracy under multi-objective adversarial training. We firmly believe that our benchmark and theoretical insights will significantly benefit the NAS community through reliable reproducibility, efficient assessment, and theoretical foundation, particularly in the pursuit of robust architectures.

Author context

Most prolific author: 13 submissions (credibility 0.50).

Delta if applied: -0.3 percentile

Aggregate statistics only — no individual author rankings.

Ranking trajectory

Percentile by tournament round — convergence indicates rating stability.

Judge assessments

Mean overall score 0.0 ± 0.0 (n = 34)