<?xml version="1.0" encoding="UTF-8"?>

<modsCollection xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.loc.gov/mods/v3" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-3.xsd">
<mods version="3.3">

<genre>preprint</genre>

<titleInfo><title>Revisiting the adversarial robustness-accuracy tradeoff in robot learning</title></titleInfo>


<note type="publicationStatus">draft</note>



<name type="personal">
  <namePart type="given">Mathias</namePart>
  <namePart type="family">Lechner</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">3DC22916-F248-11E8-B48F-1D18A9856A87</identifier></name>
<name type="personal">
  <namePart type="given">Alexander</namePart>
  <namePart type="family">Amini</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>
<name type="personal">
  <namePart type="given">Daniela</namePart>
  <namePart type="family">Rus</namePart>
  <role><roleTerm type="text">author</roleTerm> </role></name>
<name type="personal">
  <namePart type="given">Thomas A</namePart>
  <namePart type="family">Henzinger</namePart>
  <role><roleTerm type="text">author</roleTerm> </role><identifier type="local">40876CD8-F248-11E8-B48F-1D18A9856A87</identifier><description xsi:type="identifierDefinition" type="orcid">0000-0002-2985-7724</description></name>







<name type="corporate">
  <namePart></namePart>
  <identifier type="local">ToHe</identifier>
  <role>
    <roleTerm type="text">department</roleTerm>
  </role>
</name>





<name type="corporate">
  <namePart>Vigilant Algorithmic Monitoring of Software</namePart>
  <role><roleTerm type="text">project</roleTerm></role>
</name>



<abstract lang="eng">Adversarial training (i.e., training on adversarially perturbed input data) is a well-studied method for making neural networks robust to potential adversarial attacks during inference. However, the improved robustness does not
come for free but rather is accompanied by a decrease in overall model accuracy and performance. Recent work has shown that, in practical robot learning applications, the effects of adversarial training do not pose a fair trade-off
but inflict a net loss when measured in holistic robot performance. This work revisits the robustness-accuracy trade-off in robot learning by systematically analyzing if recent advances in robust training methods and theory in
conjunction with adversarial robot learning can make adversarial training suitable for real-world robot applications. We evaluate a wide variety of robot learning tasks ranging from autonomous driving in a high-fidelity environment
amenable to sim-to-real deployment, to mobile robot gesture recognition. Our results demonstrate that, while these techniques make incremental improvements on the trade-off on a relative scale, the negative side-effects caused by
adversarial training still outweigh the improvements by an order of magnitude. We conclude that more substantial advances in robust learning methods are necessary before they can benefit robot learning tasks in practice.</abstract>

<originInfo><dateIssued encoding="w3cdtf">2022</dateIssued>
</originInfo>
<language><languageTerm authority="iso639-2b" type="code">eng</languageTerm>
</language>



<relatedItem type="host"><titleInfo><title>arXiv</title></titleInfo>
  <identifier type="arXiv">2204.07373</identifier><identifier type="doi">10.48550/arXiv.2204.07373</identifier>
<part>
</part>
</relatedItem>
<relatedItem type="Supplementary material">
  <location>     <url>https://research-explorer.ista.ac.at/record/12704</url>     <url>https://research-explorer.ista.ac.at/record/11362</url>  </location>
</relatedItem>

<extension>
<bibliographicCitation>
<ieee>M. Lechner, A. Amini, D. Rus, and T. A. Henzinger, “Revisiting the adversarial robustness-accuracy tradeoff in robot learning,” &lt;i&gt;arXiv&lt;/i&gt;. .</ieee>
<chicago>Lechner, Mathias, Alexander Amini, Daniela Rus, and Thomas A Henzinger. “Revisiting the Adversarial Robustness-Accuracy Tradeoff in Robot Learning.” &lt;i&gt;ArXiv&lt;/i&gt;, n.d. &lt;a href=&quot;https://doi.org/10.48550/arXiv.2204.07373&quot;&gt;https://doi.org/10.48550/arXiv.2204.07373&lt;/a&gt;.</chicago>
<apa>Lechner, M., Amini, A., Rus, D., &amp;#38; Henzinger, T. A. (n.d.). Revisiting the adversarial robustness-accuracy tradeoff in robot learning. &lt;i&gt;arXiv&lt;/i&gt;. &lt;a href=&quot;https://doi.org/10.48550/arXiv.2204.07373&quot;&gt;https://doi.org/10.48550/arXiv.2204.07373&lt;/a&gt;</apa>
<ista>Lechner M, Amini A, Rus D, Henzinger TA. Revisiting the adversarial robustness-accuracy tradeoff in robot learning. arXiv, 2204.07373.</ista>
<short>M. Lechner, A. Amini, D. Rus, T.A. Henzinger, ArXiv (n.d.).</short>
<ama>Lechner M, Amini A, Rus D, Henzinger TA. Revisiting the adversarial robustness-accuracy tradeoff in robot learning. &lt;i&gt;arXiv&lt;/i&gt;. doi:&lt;a href=&quot;https://doi.org/10.48550/arXiv.2204.07373&quot;&gt;10.48550/arXiv.2204.07373&lt;/a&gt;</ama>
<mla>Lechner, Mathias, et al. “Revisiting the Adversarial Robustness-Accuracy Tradeoff in Robot Learning.” &lt;i&gt;ArXiv&lt;/i&gt;, 2204.07373, doi:&lt;a href=&quot;https://doi.org/10.48550/arXiv.2204.07373&quot;&gt;10.48550/arXiv.2204.07373&lt;/a&gt;.</mla>
</bibliographicCitation>
</extension>
<recordInfo><recordIdentifier>11366</recordIdentifier><recordCreationDate encoding="w3cdtf">2022-05-12T13:20:17Z</recordCreationDate><recordChangeDate encoding="w3cdtf">2026-04-07T14:21:58Z</recordChangeDate>
</recordInfo>
</mods>
</modsCollection>
