cs.LGJul 23, 2025

On the Interaction of Compressibility and Adversarial Robustness

Authors: Melih Barsbey, Antônio H. Ribeiro, Umut Şimşekli, Tolga Birdal

Organizations: Department of Computing, Imperial College London, UK · Department of Information Technology, Uppsala University, Sweden · INRIA, CNRS, Département d’Informatique de l’Ecole Normale Supérieure / PSL, France

Abstract

As demands for resource efficiency and safety in modern neural networks intensify, substantial research effort has gone into model compression and adversarial robustness. Yet despite progress on each in isolation, a systematic understanding of how compressibility shapes robustness remains elusive. In this paper, we develop a principled framework to analyze how different forms of structured compressibility - such as neuron-level and spectral compressibility - affect adversarial robustness. We show that structured compressibility can induce a small number of highly sensitive directions in the representation space, which adversaries can exploit to construct effective perturbations. Our analysis yields a robustness bound that reveals how neuron and spectral compressibility impact ℓ∞\ell_\infty and ℓ2\ell_2 robustness via their effects on the learned representations. Crucially, the vulnerabilities we identify arise irrespective of how compressibility is achieved - whether via regularization, architectural bias, or learning dynamics. Through empirical evaluations across synthetic and realistic tasks, we confirm our theoretical predictions, and further demonstrate that these vulnerabilities persist under adversarial training and transfer learning, and contribute to the emergence of universal adversarial examples. Our findings show a fundamental tension between structured compressibility and robustness and highlight new pathways for designing models that are efficient and safe.

Figures & tables

Appendix figures & tables23 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Understanding Fault Tolerance of Adversarially Robust Pruned Models

    Aug 4, 2026Manali Dangarikar, Cory MerkelModern Deep NetworksStructured Pruning

  2. On the Interaction Between Model Compression and Test-Time Adaptation

    Sep 3, 2026Francesco Corti, Dong Wang, Young D. Kwon +2Stable Test-Time AdaptationCompressed Model

  3. Robustness Cannot be Reduced to Regularization: Studying Adversarial Training Beyond the Linear Case

    Jun 19, 2026David A. R. Robin, Rafael Pinot, Yann ChevaleyreAdversarial TrainingAdversarial Examples