Thanks to their extensive capacity, over-parameterized neural networks exhibit superior predictive capabilities and generalization. Nevertheless, having a large parameter space is considered one of the main suspects of the neural network vulnerability to adversarial examples– input samples crafted ad hoc to induce a desired misclassification. The relevant literature has presented contradictory claims regarding the robustness of over-parameterized networks. These contradictory findings might be due to the failure of the attack employed to evaluate the robustness of the networks. Previous research has demonstrated that depending on the considered model, the algorithm employed to generate adversarial examples may not function properly, leading to overestimating its robustness. In this work, we empirically study the robustness of over-parameterized networks against adversarial examples. However, unlike the previous works, we also evaluate the considered attack’s reliability, employing the tools at the state of the art, to support the results’ veracity. Our results show that over-parameterized networks are more robust to adversarial attacks than their under-parameterized counterparts.

Over-parameterization and adversarial robustness in neural networks: an overview and empirical analysis

Gupta, Srishti
Primo
;
Demetrio, Luca;Brau, Fabio;Cinà, Antonio Emanuele;Pintor, Maura;Oneto, Luca;Demontis, Ambra
;
Biggio, Battista;
2026-01-01

Abstract

Thanks to their extensive capacity, over-parameterized neural networks exhibit superior predictive capabilities and generalization. Nevertheless, having a large parameter space is considered one of the main suspects of the neural network vulnerability to adversarial examples– input samples crafted ad hoc to induce a desired misclassification. The relevant literature has presented contradictory claims regarding the robustness of over-parameterized networks. These contradictory findings might be due to the failure of the attack employed to evaluate the robustness of the networks. Previous research has demonstrated that depending on the considered model, the algorithm employed to generate adversarial examples may not function properly, leading to overestimating its robustness. In this work, we empirically study the robustness of over-parameterized networks against adversarial examples. However, unlike the previous works, we also evaluate the considered attack’s reliability, employing the tools at the state of the art, to support the results’ veracity. Our results show that over-parameterized networks are more robust to adversarial attacks than their under-parameterized counterparts.
2026
Over-parameterization; Adversarial robustness; Reliable evaluation
File in questo prodotto:
File Dimensione Formato  
s44163-026-01621-5.pdf

accesso aperto

Tipologia: versione editoriale (VoR)
Dimensione 3.09 MB
Formato Adobe PDF
3.09 MB Adobe PDF Visualizza/Apri

I metadati presenti in IRIS UNICA sono rilasciati con licenza Creative Commons CC0 1.0 Universal, mentre i file delle pubblicazioni sono protetti da diritto d'autore, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11584/493046
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
  • OpenAlex 0
social impact