{"id":"https://openalex.org/W7133852981","doi":"https://doi.org/10.48550/arxiv.2603.03507","title":"Solving adversarial examples requires solving exponential misalignment","display_name":"Solving adversarial examples requires solving exponential misalignment","publication_year":2026,"publication_date":"2026-03-03","ids":{"openalex":"https://openalex.org/W7133852981","doi":"https://doi.org/10.48550/arxiv.2603.03507"},"language":null,"primary_location":{"id":"pmh:doi:10.48550/arxiv.2603.03507","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":null,"any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5115817528","display_name":"Alessandro Salvatore","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Salvatore, Alessandro","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5082696325","display_name":"Stanislav Fort","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Fort, Stanislav","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5056551357","display_name":"Surya Ganguli","orcid":"https://orcid.org/0000-0002-9264-7551"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ganguli, Surya","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5115817528"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9681000113487244,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9681000113487244,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.013799999840557575,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.0020000000949949026,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7663000226020813},{"id":"https://openalex.org/keywords/curse-of-dimensionality","display_name":"Curse of dimensionality","score":0.7537000179290771},{"id":"https://openalex.org/keywords/exponential-growth","display_name":"Exponential growth","score":0.6729000210762024},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.588699996471405},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.5238000154495239},{"id":"https://openalex.org/keywords/exponential-function","display_name":"Exponential function","score":0.4659000039100647},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4564000070095062}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7663000226020813},{"id":"https://openalex.org/C111030470","wikidata":"https://www.wikidata.org/wiki/Q1430460","display_name":"Curse of dimensionality","level":2,"score":0.7537000179290771},{"id":"https://openalex.org/C75235859","wikidata":"https://www.wikidata.org/wiki/Q582659","display_name":"Exponential growth","level":2,"score":0.6729000210762024},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.588699996471405},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5461999773979187},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.5238000154495239},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4733999967575073},{"id":"https://openalex.org/C151376022","wikidata":"https://www.wikidata.org/wiki/Q168698","display_name":"Exponential function","level":2,"score":0.4659000039100647},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4564000070095062},{"id":"https://openalex.org/C529865628","wikidata":"https://www.wikidata.org/wiki/Q1790740","display_name":"Manifold (fluid mechanics)","level":2,"score":0.40630000829696655},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.3977000117301941},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.3310000002384186},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.301800012588501},{"id":"https://openalex.org/C2778572836","wikidata":"https://www.wikidata.org/wiki/Q380933","display_name":"Space (punctuation)","level":2,"score":0.2867000102996826},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.27219998836517334},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.2700999975204468},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.26989999413490295},{"id":"https://openalex.org/C122041747","wikidata":"https://www.wikidata.org/wiki/Q838611","display_name":"Ball (mathematics)","level":2,"score":0.26489999890327454},{"id":"https://openalex.org/C50335755","wikidata":"https://www.wikidata.org/wiki/Q483247","display_name":"Phenomenon","level":2,"score":0.2500999867916107}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:doi:10.48550/arxiv.2603.03507","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},{"id":"doi:10.48550/arxiv.2603.03507","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.03507","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:doi:10.48550/arxiv.2603.03507","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Adversarial":[0],"attacks":[1],"-":[2,12],"input":[3,130,133],"perturbations":[4],"imperceptible":[5],"to":[6,52,100,138,171,220,247],"humans":[7],"that":[8,53,61,147,214],"fool":[9],"neural":[10,65],"networks":[11,189,201],"remain":[13],"both":[14,166],"a":[15,23,35,41,110,121,126,244],"persistent":[16],"failure":[17],"mode":[18],"in":[19],"machine":[20,157,241],"learning,":[21],"and":[22,33,92,158,161,169,206,230,233],"phenomenon":[24],"with":[25,84,94,178],"mysterious":[26],"origins.":[27],"To":[28],"shed":[29],"light,":[30],"we":[31,195],"define":[32],"analyze":[34],"network's":[36,122],"perceptual":[37],"manifold":[38],"(PM)":[39],"for":[40,114],"class":[42,54,140],"concept":[43],"as":[44],"the":[45,56,62,115,179,198,208,226,235],"space":[46],"of":[47,64,70,75,117,129,156,190,215,228,237,240],"all":[48],"inputs":[49,97],"confidently":[50,98],"assigned":[51,99],"by":[55,102],"network.":[57],"We":[58,182],"find,":[59],"strikingly,":[60],"dimensionalities":[63],"network":[66],"PMs":[67,210,242],"are":[68,202],"orders":[69],"magnitude":[71],"higher":[72],"than":[73],"those":[74],"natural":[76,111],"human":[77,159,216,221],"concepts.":[78],"Since":[79],"volume":[80],"typically":[81],"grows":[82],"exponentially":[83,95,204],"dimension,":[85],"this":[86,108],"suggests":[87,146],"exponential":[88],"misalignment":[89],"between":[90],"machines":[91,103],"humans,":[93],"many":[96],"concepts":[101,217],"but":[104],"not":[105],"humans.":[106],"Furthermore,":[107],"provides":[109],"geometric":[112],"hypothesis":[113,144],"origin":[116],"adversarial":[118,148,231,248],"examples:":[119],"because":[120],"PM":[123,173,180],"fills":[124],"such":[125],"large":[127],"region":[128],"space,":[131],"any":[132,139,172],"will":[134],"be":[135,151,175],"very":[136],"close":[137],"concept's":[141],"PM.":[142],"Our":[143,223],"thus":[145],"robustness":[149],"cannot":[150],"attained":[152],"without":[153],"dimensional":[154],"alignment":[155,219,229],"PMs,":[160],"therefore":[162],"makes":[163],"strong":[164],"predictions:":[165],"robust":[167,192,200],"accuracy":[168],"distance":[170],"should":[174],"negatively":[176],"correlated":[177],"dimension.":[181],"confirmed":[183],"these":[184],"predictions":[185],"across":[186],"18":[187],"different":[188],"varying":[191],"accuracy.":[193],"Crucially,":[194],"find":[196],"even":[197],"most":[199],"still":[203],"misaligned,":[205],"only":[207],"few":[209],"whose":[211],"dimensionality":[212,239],"approaches":[213],"exhibit":[218],"perception.":[222],"results":[224],"connect":[225],"fields":[227],"examples,":[232],"suggest":[234],"curse":[236],"high":[238],"is":[243],"major":[245],"impediment":[246],"robustness.":[249]},"counts_by_year":[],"updated_date":"2026-05-03T08:25:01.440150","created_date":"2026-03-06T00:00:00"}
