Fisher Information Spectral Norm Gives Attack-Agnostic Robustness Metric for DNNs
June 2, 2026
The spectral norm of the Fisher Information Matrix quantifies worst-case output sensitivity to input perturbations without requiring adversarial attacks, with closed-form bounds derived for VGG, ResNet, DenseNet, and Transformer architectures. Efficient estimation via power iteration and Hutchinson's method supports both white-box and black-box evaluation.
HOW THIS AFFECTS YOU
●
researcherFirst theoretical robustness ranking across major architectures using FIM spectral bounds is a useful reference point, though practical gap to attack-based evaluation needs validation.