Abstract
Standardized benchmarks like RobustBench are crucial for evaluating adversarial robustness. However, the increasing dominance of models trained on massive synthetic datasets (orders of magnitude larger than original training sets) raises questions about reported performance gains. This work identifies and investigates a potential inflation factor: high feature-level similarity between large-scale synthetic training data and benchmark test sets. We argue this similarity is an inherent characteristic arising from the probabilistic generation process of these large datasets, which naturally produces examples highly similar to test instances in feature space. This creates what we term an “Implicit Information Advantage,” where models effectively train on near-duplicates of test instances. Through comprehensive empirical analysis, we demonstrate that: (1) Synthetic datasets exhibit significantly higher similarity to the test set compared to the original training data. (2) A direct correlation exists between this similarity and robustness outcomes, with test images benefiting most having the highest similarity scores. (3) Strikingly, ablation studies show that training on just a small fraction (e.g., 1%) of the most similar synthetic examples can yield robustness comparable to using the full massive dataset. These findings suggest current benchmarks may overestimate true robust generalization due to this similarity artifact. We call for revised evaluation protocols and greater transparency to ensure benchmarks accurately measure true generalization. Code and data can be found in https://github.com/fzjcdt/RethinkingRobustBench.
| Original language | English |
|---|---|
| Title of host publication | 2025 IEEE 12th International Conference on Data Science and Advanced Analytics, DSAA 2025 |
| Publisher | IEEE |
| Number of pages | 10 |
| ISBN (Electronic) | 9798331511791 |
| ISBN (Print) | 9798331511807 |
| DOIs | |
| Publication status | Published - 24 Nov 2025 |
| Event | 2025 IEEE 12th International Conference on Data Science and Advanced Analytics (DSAA) - Birmingham, United Kingdom, Birmingham, United Kingdom Duration: 9 Oct 2025 → 12 Oct 2025 |
Publication series
| Name | Proceedings of the International Conference on Data Science and Advanced Analytics |
|---|---|
| ISSN (Print) | 2472-1573 |
| ISSN (Electronic) | 2766-4112 |
Conference
| Conference | 2025 IEEE 12th International Conference on Data Science and Advanced Analytics (DSAA) |
|---|---|
| Country/Territory | United Kingdom |
| City | Birmingham |
| Period | 9/10/25 → 12/10/25 |
Bibliographical note
Publisher Copyright:© 2025 IEEE.
Funding
We thank the anonymous reviewers for their insightful comments. This work was supported by the National Natural Science Foundation of China under Grant 62250710682, Guangdong Provincial Key Laboratory under Grant 2020B121201001, and the Program for Guangdong Introducing Innovative and Entrepreneurial Teams under Grant 2017ZT07X386.
Keywords
- Adversarial Robustness
- Implicit Information Advantage
- Synthetic Data
Fingerprint
Dive into the research topics of 'Rethinking RobustBench: Is High Synthetic-Test Data Similarity an Implicit Information Advantage Inflating Robustness Scores?'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver