Pith. sign in

REVIEW 2 cited by

The mathematics of adversarial attacks in AI -- Why deep learning is unstable despite the existence of stable neural networks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2109.06098 v2 pith:ZW2U22N5 submitted 2021-09-13 cs.LG cs.CVcs.NAmath.NAstat.ML

classification cs.LGcs.CVcs.NAmath.NAstat.ML
keywords networksneuralaccurateexistenceproblemsstableclassificationcompute
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

The unprecedented success of deep learning (DL) makes it unchallenged when it comes to classification problems. However, it is well established that the current DL methodology produces universally unstable neural networks (NNs). The instability problem has caused an enormous research effort -- with a vast literature on so-called adversarial attacks -- yet there has been no solution to the problem. Our paper addresses why there has been no solution to the problem, as we prove the following mathematical paradox: any training procedure based on training neural networks for classification problems with a fixed architecture will yield neural networks that are either inaccurate or unstable (if accurate) -- despite the provable existence of both accurate and stable neural networks for the same classification problems. The key is that the stable and accurate neural networks must have variable dimensions depending on the input, in particular, variable dimensions is a necessary condition for stability. Our result points towards the paradox that accurate and stable neural networks exist, however, modern algorithms do not compute them. This yields the question: if the existence of neural networks with desirable properties can be proven, can one also find algorithms that compute them? There are cases in mathematics where provable existence implies computability, but will this be the case for neural networks? The contrary is true, as we demonstrate how neural networks can provably exist as approximate minimisers to standard optimisation problems with standard cost functions, however, no randomised algorithm can compute them with probability better than 1/2.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. An incremental algorithm for non-convex AI-enhanced medical image processing

    cs.CV 2025-05 conditional novelty 5.0 of 10

    incDG inserts a deep-network estimate at every incremental TpV step, giving faster and more stable deblurring and CT reconstructions than either the pure model-based or pure deep-learning baselines, with slightly lowe...

  2. Hallucinations in medical devices

    eess.IV 2025-08 conditional novelty 4.0 of 10

    AI hallucinations in medical devices are defined as plausible errors, either impactful or benign, to guide device evaluation.

Pith tools