BatchNorm Layers have an Outsized Effect on Adversarial Robustness

Published: 22 Sept 2025, Last Modified: 01 Dec 2025NeurIPS 2025 WorkshopEveryoneRevisionsBibTeXCC BY 4.0
Keywords: adversarial training, BatchNorm
Abstract: Training different layers differently may affect resulting adversarial robustness and clean accuracy in adversarial training. We focus on the BatchNorm layers and study their unique role in adversarial training. Through a partial adversarial (pre-)training methodology we investigate how different optimization strategies for the BatchNorm layers affect adversarial robustness, and interplay with other model design choices.
Submission Number: 135
Loading