>

>

Geometry Is Not Robustness: A Trajectory-Level Study of PGD Evaluation

Geometry Is Not Robustness: A Trajectory-Level Study of PGD Evaluation | RISE Research

Focus

Adversarial Robustness Evaluation, PGD Attack Trajectory Analysis, Deep Learning Diagnostics

Motivation

Adversarial Machine Learning, Model Robustness, Evaluation Methodology

About the project

This paper investigates whether trajectory-level diagnostics of Projected Gradient Descent (PGD) adversarial attacks, beyond just final adversarial accuracy, reliably indicate a deep learning model's true robustness. The authors train a compact CNN on Fashion-MNIST under three regimes (clean training, and adversarial training at perturbation budgets epsilon = 0.1 and epsilon = 0.2), then record complete 20-step PGD attack trajectories across 3,000 clean-correct samples per model, analyzing loss evolution, gradient cosine-similarity (directional stability), and steps-to-failure (the iteration at which a model's prediction first flips). The clean-trained model collapses immediately under attack (0% robust accuracy), while the two adversarially trained models diverge sharply in robust accuracy at epsilon = 0.2 (8.35% vs. 68.24%) despite showing nearly identical mean loss trajectories and, in one case, counterintuitively lower early-step gradient alignment for the more robust model. This finding reveals that smooth, stable-looking optimization geometry, as captured by loss curves and gradient alignment, does not reliably track functional robustness strength. By contrast, steps-to-failure distributions clearly separated the three robustness regimes, since they directly measure how long a model resists perturbation rather than describing the smoothness of the attack path. The paper concludes that trajectory-level diagnostics offer valuable descriptive insight into adversarial optimization dynamics but should not replace, and can actively mislead if substituted for, standard robust-accuracy evaluation; researchers should treat trajectory metrics as a complementary, multi-metric diagnostic tool rather than a standalone robustness proxy. The study is limited to a single dataset and compact architecture, and suggests future work incorporate stronger ensemble attacks like AutoAttack for further validation.

Want to build a standout academic profile?

Interested in research mentorship?

Book a free call
Book a free call

Check out more projects

Emerging Clinical Strategies in Cholangiocarcinoma: A Review on Targeted Therapy and Immunotherapy

By :

Vanshika G.

View

From Rule-Based to Self-Improving Agents: The Evolution of AI Price Collusion

By :

Sanya S.

View

Within a single food category (snacks) on Blinkit, do products with nutrition marketing labels receive significantly different customer ratings than unlabelled products?

By :

Aahana B.

View

Emerging Clinical Strategies in Cholangiocarcinoma: A Review on Targeted Therapy and Immunotherapy

By :

Vanshika G.

View

From Rule-Based to Self-Improving Agents: The Evolution of AI Price Collusion

By :

Sanya S.

View

How to Apply

1.

Parent Consultation Call

2.

⁠Research Application Form

3.

⁠Profile Shortlisting

4.

⁠Program Onboarding

How to Apply

1.

Parent Consultation Call

2.

⁠Research Application Form

3.

⁠Profile Shortlisting

4.

⁠Program Onboarding

How to Apply

1.

Parent Consultation Call

2.

⁠Research Application Form

3.

⁠Profile Shortlisting

4.

⁠Program Onboarding

RISE Research Logo - Rise Global Education - Rise Research

+1 (650)-910-5964
admin@riseresearch.com

650 California St Fl 7, San Francisco, CA 94108

Copyright © 2025 RISE Research

All rights reserved.