cs.LGOct 6, 2026

Adversarially Trained Linear Transformers Are Optimal Robust In-Context Learners for Gaussian Mixtures

Authors: Soichiro Kumano

Organizations: LY Corporation

Abstract

Adversarial training is one of the most reliable defenses against adversarial attacks, but its high computational cost must generally be paid anew for each task. Robust foundation models offer a promising alternative: adversarially pretrain a model once and then transfer its robustness to downstream tasks through lightweight adaptation. However, a fundamental question remains open: can robustness acquired during pretraining transfer to unseen tasks without further adversarial training? In this study, we answer this question affirmatively. A single model adversarially pretrained at scale can achieve optimal robustness on new tasks without additional task-specific training. Specifically, we show that, for a family of Gaussian-mixture classification tasks, a sufficiently deep linear transformer adversarially trained across tasks can asymptotically attain the robust Bayes error on previously unseen tasks through in-context learning from clean demonstrations. By contrast, a standardly trained model cannot. We further analyze convergence under gradient flow, an accuracy--robustness trade-off, and demonstration complexity.

Figures & tables

Appendix figures & tables2 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Certified Robustness from Approximate Gaussian Mixture Structures in Pretrained Latent Spaces

    May 25, 2026Konstantinos Emmanouilidis, Tianjiao Ding, Nghia Nguyen +2Adversarial TrainingRobustness Verification

  2. Probabilistic Adversarial Training

    Sep 30, 2026Andi Zhang, Xingyu Zhao, Siddartha KhastgirAdversarial TrainingKullback-Leibler Divergence

  3. Robustness Cannot be Reduced to Regularization: Studying Adversarial Training Beyond the Linear Case

    Jun 19, 2026David A. R. Robin, Rafael Pinot, Yann ChevaleyreAdversarial TrainingAdversarial Examples