March 2026

Conference Paper

Exploring Black-box Adversarial Attacks on Low-rank Constrained Neural Networks

By:
Schnake, Stefan R; Park, Hwan Hee ; Schotthoefer, Steffen
Book Title:
Proceedings of 2025 Neural Information Processing Systems (NeurIPS 2025) Workshop on Constrained Optimization for Machine Learning
Publication Date:
March 2026
Conference Name:
39th Annual Conference on Neural Information Processing Systems (NeurIPS 2025), Workshop on Constrained Optimization for Machine Learning
Conference Location:
San Diego, California, United States of America
Conference Sponsor:
Neural Information Processing Systems Foundation

Abstract

Low-rank compression has been shown as an effective tool to reduce parameter counts of convolutional and vision transformer architectures; however, low-rank training often reduces model robustness to adversarial perturbations. In this work, we explore the effects of low-rank training on black-box attacks, where attacked images are generated without knowledge of the low-rank parameters. We find that low-rank training is not sufficient as a black-box defense and can sometimes produce worse than expected as compared to baseline models. Influencing the spectrum of the low-rank models during training, which is known to increase model robustness against white-box attacks, improves black-box performance as well.