Thanks to their extensive capacity, over-parameterized neural networks exhibit superior predictive capabilities and generalization. Nevertheless, having a large parameter space is considered one of the main suspects of the neural network vulnerability to adversarial examples– input samples crafted ad hoc to induce a desired misclassification. The relevant literature has presented contradictory claims regarding the robustness of over-parameterized networks. These contradictory findings might be due to the failure of the attack employed to evaluate the robustness of the networks. Previous research has demonstrated that depending on the considered model, the algorithm employed to generate adversarial examples may not function properly, leading to overestimating its robustness. In this work, we empirically study the robustness of over-parameterized networks against adversarial examples. However, unlike the previous works, we also evaluate the considered attack’s reliability, employing the tools at the state of the art, to support the results’ veracity. Our results show that over-parameterized networks are more robust to adversarial attacks than their under-parameterized counterparts.
Over-parameterization and adversarial robustness in neural networks: an overview and empirical analysis
Gupta, SrishtiPrimo
;Demetrio, Luca;Brau, Fabio;Cinà, Antonio Emanuele;Pintor, Maura;Oneto, Luca;Demontis, Ambra
;Biggio, Battista;
2026-01-01
Abstract
Thanks to their extensive capacity, over-parameterized neural networks exhibit superior predictive capabilities and generalization. Nevertheless, having a large parameter space is considered one of the main suspects of the neural network vulnerability to adversarial examples– input samples crafted ad hoc to induce a desired misclassification. The relevant literature has presented contradictory claims regarding the robustness of over-parameterized networks. These contradictory findings might be due to the failure of the attack employed to evaluate the robustness of the networks. Previous research has demonstrated that depending on the considered model, the algorithm employed to generate adversarial examples may not function properly, leading to overestimating its robustness. In this work, we empirically study the robustness of over-parameterized networks against adversarial examples. However, unlike the previous works, we also evaluate the considered attack’s reliability, employing the tools at the state of the art, to support the results’ veracity. Our results show that over-parameterized networks are more robust to adversarial attacks than their under-parameterized counterparts.| File | Dimensione | Formato | |
|---|---|---|---|
|
s44163-026-01621-5.pdf
accesso aperto
Tipologia:
versione editoriale (VoR)
Dimensione
3.09 MB
Formato
Adobe PDF
|
3.09 MB | Adobe PDF | Visualizza/Apri |
I metadati presenti in IRIS UNICA sono rilasciati con licenza Creative Commons CC0 1.0 Universal, mentre i file delle pubblicazioni sono protetti da diritto d'autore, salvo diversa indicazione.



