cd /news/artificial-intelligence/geometry-is-not-robustness-a-traject… · home › topics › artificial-intelligence › article
[ARTICLE · art-100781] src=arxiv.org ↗ pub= topic=artificial-intelligence verified=true sentiment=· neutral

Geometry Is Not Robustness: A Trajectory-Level Study of PGD Evaluation

A new study from arXiv (arXiv:2608.14594v1) finds that trajectory-level diagnostics from Projected Gradient Descent (PGD) attacks, such as loss evolution and gradient alignment, do not independently measure adversarial robustness, while steps-to-failure distributions provide clearer separation of robustness regimes. The researchers evaluated clean-trained and adversarially-trained convolutional neural networks on Fashion-MNIST using 20-step PGD attacks with random initialization and multiple restarts, recording full trajectories across 3000 clean-correct samples per model. The findings suggest trajectory-level analysis should complement, not replace, standard robustness measurements.

read1 min views19 publishedAug 18, 2026

arXiv:2608.14594v1 Announce Type: new Abstract: Projected Gradient Descent (PGD) is widely used to evaluate adversarial robustness, typically via final adversarial accuracy, which does not capture model behaviour throughout the attack. Recent work proposes trajectory-level diagnostics, such as loss evolution, gradient alignment, and steps-to-failure, for deeper insight into adversarial optimisation dynamics. However, whether these diagnostics reliably indicate robustness strength remains unclear. We conduct a trajectory-level investigation of PGD attacks on convolutional neural networks trained on Fashion-MNIST. We compare clean-trained and adversarially-trained models across multiple robustness regimes, using rigorous 20-step PGD evaluations with random initialisation and multiple restarts for robustness measurement, and single-initialisation trajectory recording for diagnostics. We record full PGD trajectories across 3000 clean-correct samples per model and analyse loss evolution, gradient alignment, and failure timing across attack iterations. Our results reveal a clear robustness hierarchy across models; however, trajectory metrics do not contribute equally to its identification. Mean loss trajectories and gradient alignment patterns appear quantitatively similar across adversarially-trained models with substantially different robust accuracies. In contrast, steps-to-failure distributions provide a clearer separation of robustness regimes, directly reflecting functional resistance to adversarial perturbation. These findings indicate that trajectory-level diagnostics describe optimisation geometry but do not independently measure adversarial robustness. Their interpretability depends on robustness regime, attack strength, and multi-metric evaluation. Trajectory-level analysis should be a complementary diagnostic tool, interpreted in context, rather than a replacement for standard robustness measurements.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @arxiv 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/geometry-is-not-robu…] indexed:0 read:1min 2026-08-18 · —