Robustness in Deep Neural Networks
DOI:
https://doi.org/10.5281/zenodo.19614740Keywords:
adversarial robustness; adversarial training; certified defences; randomised smoothing; distribution shift; TRADES; AutoAttack; robustness-accuracy trade-offAbstract
Deep neural networks achieve remarkable accuracy on clean test data yet remain brittle under distribution shift and adversarial perturbations -- small, imperceptible changes to inputs that reliably cause misclassification. This fragility raises serious safety concerns for deployed AI systems in medical imaging, autonomous driving, and security-critical applications. This study presents a controlled evaluation of six robustness techniques -- adversarial training (PGD-AT), TRADES (trading natural accuracy for robustness), randomised smoothing for certified robustness, data augmentation strategies (AugMax, AutoAugment), model architecture modifications (WideResNet with dropout), and ensemble adversarial training -- across four robustness dimensions: adversarial robustness (PGD-20, AutoAttack), distribution shift robustness (ImageNet-C, ImageNet-R), certified radius, and natural accuracy on CIFAR-10, CIFAR-100, and ImageNet. A total of 2,040 experiments were conducted. TRADES achieved the best adversarial robustness on CIFAR-10 (AutoAttack accuracy = 58.4 +- 0.4%) at a 4.8-point natural accuracy cost (87.2% vs. 92.0% for standard training). Randomised smoothing provided certified robustness guarantees (L2 radius = 0.84 +- 0.04 at 75% certified accuracy on CIFAR-10), the only method with a provable guarantee against all attacks within the certified radius. AugMax data augmentation improved distribution shift robustness by 6.8% on ImageNet-C without adversarial training overhead. Ensemble adversarial training achieved the best natural-robust Pareto point (natural 88.6%, AutoAttack 56.4%) but at 3x training cost. The fundamental trade-off between natural accuracy and adversarial robustness was confirmed: no method simultaneously achieved both > 90% natural and > 60% robust accuracy. A practical robustness deployment guide mapping threat model, acceptable natural accuracy reduction, and computational budget is proposed.Downloads
Published
2026-08-19
Issue
Section
Articles
How to Cite
Robustness in Deep Neural Networks. (2026). Bio-QI Journal, 2(4), 184-191. https://doi.org/10.5281/zenodo.19614740

