Pith. sign in

REVIEW 6 cited by

Adversarial Examples Are Not Bugs, They Are Features

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1905.02175 v4 pith:NOH26SHK submitted 2019-05-06 stat.ML cs.CRcs.CVcs.LG

classification stat.MLcs.CRcs.CVcs.LG
keywords featuresadversarialexamplesdataexistenceattentionattractedattributed
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Adversarial examples have attracted significant attention in machine learning, but the reasons for their existence and pervasiveness remain unclear. We demonstrate that adversarial examples can be directly attributed to the presence of non-robust features: features derived from patterns in the data distribution that are highly predictive, yet brittle and incomprehensible to humans. After capturing these features within a theoretical framework, we establish their widespread existence in standard datasets. Finally, we present a simple setting where we can rigorously tie the phenomena we observe in practice to a misalignment between the (human-specified) notion of robustness and the inherent geometry of the data.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 6 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. OpenAlex reports about 395 citations worldwide. Full citation record

  1. Adversarial Examples Are Not Bugs, They Are Superposition

    cs.LG 2025-08 unverdicted novelty 6.0 of 10

    The paper argues that adversarial examples arise from superposition, and shows that changing superposition changes robustness and vice versa in toy models and ResNet18.

  2. HEM: a margin-based loss for visual categorisation tasks

    cs.LG 2025-01 conditional novelty 6.0 of 10

    A new margin-based loss, HEM, trains image classifiers that are more robust to unknown and adversarial inputs and better at continual learning and segmentation than cross-entropy-trained models.

  3. Agent Delivery Engineering Predictive Reliability Framework

    cs.MA 2026-07 conditional novelty 5.0 of 10

    A five-layer, 20-signal Trust Margin metric and Exponential-smoothing prediction engine achieve 8-hour-ahead degradation forecasting for production LLM agent systems with MAE=1.228 and 76.8% direction accuracy.

  4. Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation

    cs.CL 2025-08 reject novelty 5.0 of 10

    Sparse autoencoder activation perturbation (SFPF) applied on top of existing jailbreak prompts raises attack success rate on Qwen3-32B, but with no defense evaluation and weak reproducibility.

  5. Position: Machine Learning Conferences Should Establish a "Refutations and Critiques" Track

    cs.LG 2025-06 conditional novelty 5.0 of 10

    ML conferences should create an official peer-reviewed track dedicated to refuting and critiquing previously published work.

  6. Direct Ascent Synthesis: Revealing Hidden Generative Capabilities in Discriminative Models

    cs.CV 2025-02 conditional novelty 5.0 of 10

    Direct Ascent Synthesis generates recognizable images from CLIP embeddings by optimizing a sum of multi-resolution image components, requiring no generative training.

Pith tools