How Robust Are Energy-Based Models Trained With Equilibrium Propagation?
Siddharth Mansingh, Michal Kucer, Garrett T. Kenyon, Juston Moore, Michael Teti
OpenReview ground truth
Abstract
Deep neural networks (DNNs) are easily fooled by adversarial perturbations that are imperceptible to humans. Adversarial training, a process where adversarial examples are added to the training set, is the current state-of-the-art defense against adversarial attacks, but it lowers the model's accuracy on clean inputs, is computationally expensive, and offers less robustness to natural noise. In contrast, energy-based models (EBMs), which were designed for efficient implementation in neuromorphic hardware and physical systems, incorporate feedback connections from each layer to the previous layer, yielding a recurrent, deep-attractor architecture which we hypothesize should make them naturally robust. Our work is the first to explore the robustness of EBMs to both natural corruptions and adversarial attacks, which we do using the CIFAR-10 and CIFAR-100 datasets. We demonstrate that EBMs are more robust than transformers and display comparable robustness to adversarially-trained DNNs on white-box, black-box, and natural perturbations without sacrificing clean accuracy, and without the need for adversarial training or additional training techniques.
Author context
Most prolific author: 3 submissions (credibility 1.00).
No mass-submission penalty for this paper (authors within normal submission volume).
Aggregate statistics only — no individual author rankings.
Ranking trajectory
Percentile by tournament round — convergence indicates rating stability.
Battle history — 30 comparisons
Ranked above opponent in 49% of matchups.
- ▼ lost to Dataset Distillation via Adversarial Predi… ×4
- ▲ beat Cosine Similarity Knowledge Distillation f… ×4
- ▼ lost to Towards Bringing Advanced Restoration Netw… ×4
- ▲ beat Con4m: Unleashing the Power of Consistency… ×4
- ▼ lost to On Adversarial Training without Perturbing… ×4
Judge assessments
Mean overall score 0.0 ± 0.0 (n = 30)