iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Maharashtra’s ₹500 crore AI agriculture policy targets data, traceability and farm advisory Commercial LPG prices drop: 19-kg cylinder rate cut by ₹202 in Delhi, ₹209 in Kolkata Commercial LPG Prices Cut by Over Rs 200; Delhi, Kolkata 19-kg Cylinder Rates Published US Stock Markets Rally as Chip Stock Gains Lift Nasdaq, S&P 500 and Dow SEBI Clarifies Unlisted Share Sale Rules: 200-Buyer Private Deal Limit GeM completes 10 years as India's trusted digital public procurement platform Moody's Assigns First-Time Baa2 Rating to RBL Bank, One Notch Above India's Sovereign Sebi Bars Zee's Subhash Chandra, Punit Goenka From Market for One Year Zepto Defers IPO by Two to Three Quarters After Tepid Investor Response Tim Cook: India Among Apple's Best Global Markets as June Quarter Records Revenue Maharashtra’s ₹500 crore AI agriculture policy targets data, traceability and farm advisory Commercial LPG prices drop: 19-kg cylinder rate cut by ₹202 in Delhi, ₹209 in Kolkata Commercial LPG Prices Cut by Over Rs 200; Delhi, Kolkata 19-kg Cylinder Rates Published US Stock Markets Rally as Chip Stock Gains Lift Nasdaq, S&P 500 and Dow SEBI Clarifies Unlisted Share Sale Rules: 200-Buyer Private Deal Limit GeM completes 10 years as India's trusted digital public procurement platform Moody's Assigns First-Time Baa2 Rating to RBL Bank, One Notch Above India's Sovereign Sebi Bars Zee's Subhash Chandra, Punit Goenka From Market for One Year Zepto Defers IPO by Two to Three Quarters After Tepid Investor Response Tim Cook: India Among Apple's Best Global Markets as June Quarter Records Revenue
Home ›› Technology ›› Ai ›› GRAPE: New Training Method Boosts Adversarial Robustness with 21% Fewer Parameters

GRAPE: New Training Method Boosts Adversarial Robustness with 21% Fewer Parameters

A new training framework called GRAPE (Guided Parameter-Space Evolution) improves adversarial robustness in neural networks by progressively exposing parameters, achieving 56.94% robust accuracy on CIFAR-10 with 21.4% fewer parameters than standard adversarial training, according to an arXiv paper.

iG
iGEN Editorial
June 16, 2026
GRAPE: New Training Method Boosts Adversarial Robustness with 21% Fewer Parameters

Enterprises deploying machine learning models in safety-critical applications—from fraud detection to autonomous logistics—face the persistent threat of adversarial attacks, where small, imperceptible input perturbations cause models to misclassify. Adversarial Training (AT) is the leading defense, but it typically demands heavy computational resources and large parameter counts. A new method, GRAPE (Guided Parameter-Space Evolution), described in a recent arXiv paper, offers a more efficient path to robust models by progressively exposing and stabilizing parameters during training.

The GRAPE Approach

GRAPE combines parameter-space stabilization with progressive hidden expansion. Rather than training a full fixed-architecture model from the start, GRAPE stabilizes robust optimization in the currently exposed parameter space, then gradually releases new optimizable dimensions. It uses an adversarial spectral utilization score to guide newly released capacity toward high-pressure modules—those that are most critical for robustness. The authors, Zhiyuan Ye, Xiangyu Zhou, Ji Qi, Hao Zhang, and Yi, argue that "the order in which parameters become optimizable can affect the final robust solution, even when the final architecture or computation budget is controlled." This treats robust model learning as a process of progressive parameter-space exposure and evolution, in contrast to fixed-structure AT.

Measured Gains on CIFAR-10

Under the standard ℓ∞ threat model on CIFAR-10, using a fixed-structure ResNet-18 as a controlled reference, GRAPE delivered significant improvements.

Method PGD-20 Robust Accuracy Parameter Count (approx.) FLOPs Ratio
Standard Adversarial Training (ResNet-18) 51.70% 100% (baseline) 1.000x
GRAPE (same final architecture) 56.94% 78.6% (21.4% reduction) 1.009x
Sequential Grow Variant (same final architecture) 56.52% ~78.6% (similar) ~1.009x

According to the paper, GRAPE improved PGD-20 robust accuracy from 51.70% to 56.94% at a nearly matched computation budget (FLOPs ratio of 1.009x), while reducing parameter count by about 21.4%. A sequential grow variant with the same final ResNet-18 architecture reached 56.52%, indicating that the gain is not solely due to final architecture but also to the parameter-space exposure path.

Implications for Enterprise AI

For enterprise technology leaders, GRAPE demonstrates that adversarial robustness can be achieved more efficiently—with fewer parameters and minimal computational overhead. This could reduce the cost of deploying secure models in edge devices or cost-sensitive environments. The method's progressive exposure may also offer insights for continual learning and model compression. While the experiments are on CIFAR-10 with ResNet-18, the framework is architecture-agnostic and could be extended to larger models and datasets, potentially enabling resilient AI systems in logistics, trade, and supply chain applications. The paper is available on arXiv under a Creative Commons license, with code and data links provided.


Sources:

Keep Reading

Recommended Stories

New Temporal Pyramid Model Enhances Spoofed Speech Detection for Voice Security Systems Technology

New Temporal Pyramid Model Enhances Spoofed Speech Detection for Voice Security Systems

Researchers introduced a Temporal Pyramid Adapter for spoofed speech detection that uses parallel temporal convolutions with varying receptive fields to capture multi-scale cues. The model achieved a 99.24% AUC and 3.87% EER on the PartialSpoof dataset, significantly outperforming existing methods like LCNN-BLSTM (9.87% EER) and TRACE (8.08% EER). The work highlights the potential for improving voice authentication security but notes performance degradation under domain and language shifts.

June 17, 2026
New LLM Framework Detects Phishing Emails with Over 90% Accuracy Technology

New LLM Framework Detects Phishing Emails with Over 90% Accuracy

A paper on arXiv introduces LLMPEA, a framework using GPT-4o, Claude Sonnet 4, and Grok-3 to detect phishing emails with over 90% accuracy. The study also reveals vulnerabilities to adversarial attacks, prompt injection, and multilingual attacks, emphasizing the need for hardening before deployment.

June 16, 2026
Beijing Accuses US AI Firms of Using Chinese Models for Training Technology

Beijing Accuses US AI Firms of Using Chinese Models for Training

The Chinese commerce ministry accused US artificial intelligence firms of using Chinese models to train their own AI systems through a process called distillation. This comes after US Treasury Secretary Scott Bessent threatened sanctions against China over alleged technology theft. China defended distillation as a widely used industry practice and vowed to take all necessary measures to safeguard its interests.

July 28, 2026
project44 CEO: AI Agents Without Context Are Just Guessing Faster Technology

project44 CEO: AI Agents Without Context Are Just Guessing Faster

project44 CEO Jett McCandless argues that AI agents require rich contextual data to be effective. The company's Agentic Workflow Manager layers first- and third-party agents on top of shipment-level data to automate tasks like LTL dispatch reconciliation, processing 75,000 dispatches daily and matching over 2,000 that would otherwise require manual intervention.

July 13, 2026