---
title: Currying ALU for Modular Adversarial Robustness
url: https://www.emergentmind.com/topics/currying-alu
type: topic
---

# Currying ALU for Modular Adversarial Robustness

Currying ALU, in the context of adversarial robustness in deep neural networks, refers to the application of the Adversarial Logit Update (ALU) principle using a curried, higher-order functional-programming style. This approach decomposes the ALU-based classification pipeline into modular, composable units—allowing independent variation of model, purifier, and decision logic. The ALU principle itself provides a decision rule for inferring class labels of adversarial or purified samples, operating on the difference between logits before and after purification. Currying this principle yields increased modularity, facilitating rapid experimentation with different purification and classification strategies while retaining adversarial robustness guarantees [2308.15072].

## 1. Theoretical Basis of Adversarial Logit Update

ALU targets adversarial robustness by observing that, when a clean sample $x$ is perturbed into an adversarial instance $x_\text{adv}=x+\delta$ and subsequently passed through a purification module $P$, the resulting logit vectors (pre- and post-purification) encode crucial information for label recovery. 

Let $C(x)=\text{Softmax}(W^\top f_0(x))$ be a pre-trained classifier where $f_0(x)\in\mathbb{R}^d$ denotes penultimate-layer features and $W\in\mathbb{R}^{d\times M}$ the final layer weights. For $x_\text{adv}$ and $x_\text{pur}=P(x_\text{adv})$, define:
- Pre-purification logits $\Pi' = W^\top f_0(x_\text{adv})$
- Post-purification logits $\Pi = W^\top f_0(x_\text{pur})$
- Logit difference $\Delta\Pi = \Pi - \Pi'$, componentwise $\Delta\pi_i = \pi_i - \pi'_i$

The ALU rule states that the index of the maximal $\Delta\pi_i$ often recovers the true class. Analytical support arises from decomposing $f_0$ into robust, non-robust, and irrelevant feature subspaces, with successful attacks causing large, positive $\Delta\pi_t$ for the target class after purification, typically exceeding $\Delta\pi_i$ for $i \ne t$ [2308.15072].

## 2. Algorithmic Implementation and Classification Pseudocode

ALU-based sample classification proceeds as follows:

1. Input sample $x$
2. Compute purified surrogate $x_\text{pur} \leftarrow P(x)$
3. Compute pre- and post-purification logits: $\Pi' = W^\top f_0(x)$, $\Pi = W^\top f_0(x_\text{pur})$
4. If adversarial detection module $D(x)$ indicates $x$ is adversarial, apply ALU: $\hat{y} \leftarrow \arg\max_i (\pi_i - \pi_i')$.
5. Otherwise, employ standard classification: $\hat{y} \leftarrow \arg\max_i \pi_i$
6. Output predicted label $\hat{y}$

This workflow enables ALU to serve as either a primary classification mechanism for suspected adversarial samples or as a complement to standard argmax/softmax-based approaches.

## 3. Functional-Programming Formulation and Currying Principle

The ALU process can be encoded as a higher-order function that takes a model and a purifier as arguments, returning a classifier:

- Uncurried form:
  $$U: (\text{Model} \times \text{Purifier}) \to (\text{Logits}_\text{pre} \times \text{Logits}_\text{post}) \to \text{Label}$$
  $$U((\text{Model}, P); (\Pi', \Pi)) = \arg\max_i (\Pi_i - \Pi'_i)$$

- Curried form:
  $$
  \begin{aligned}
  U_\text{curry} = \lambda~\text{Model}.~\lambda~\text{Purifier}.~\lambda~x.~ &\text{let}~\pi' = \text{Model}(x),~x_\text{pur} = \text{Purifier}(x),~\pi = \text{Model}(x_\text{pur})~\text{in}\\ 
  &\arg\max_i (\pi_i - \pi'_i)
  \end{aligned}
  $$
  
Each $\lambda$ binds one argument, permitting partial application. Fixing the model yields a function from purifiers to classifiers. Subsequently fixing a purifier produces a classifier function $x \to \hat{y}$. This function can be further modularized to operate directly on logits rather than samples if desired [2308.15072].

## 4. Modularity via Currying: Illustrative Examples

Currying the ALU classification process results in pronounced modularity:

- **Swapping Purifiers**: Let $P_1$, $P_2$ be purifiers,
  $$
  \begin{aligned}
  U_\text{curry}(C):&~\mathcal{P} \longmapsto (x \mapsto \arg\max_i [(W^\top f_0(\mathcal{P}(x)))_i - (W^\top f_0(x))_i])\\
  h_1 &= U_\text{curry}(C)(P_1),~h_2 = U_\text{curry}(C)(P_2)
  \end{aligned}
  $$
  The code for $h_1$, $h_2$ differs only in their choice of purifier; all other logic remains shared.

- **Plug-and-play Decision Rules**: Introducing a softmax-based decision rule,
  $$
  D_\text{soft} := \lambda(\pi',\pi).~\text{Softmax}(\pi-\pi') \\
  U'_\text{curry} = \lambda C.~\lambda P.~\lambda x.~D_\text{soft}(C(x), C(P(x)))
  $$

The modular structure enables partial application of model, purifier, or decision logic, with alterations requiring changes only to the relevant $\lambda$.

## 5. Practical Impact and Modularity Gains

Currying the ALU classifier decomposes the monolithic adversarial defense pipeline into three mutually independent axes: model architecture, purification mechanism, and decision rule. Consequently, any of these elements can be exchanged independently via partial function application, expediting configurability and experimentation. For instance, one may fix a classifier while systematically evaluating multiple purification approaches, or substitute alternative decision metrics such as thresholded or softmax rules for $\arg\max$, without recoding the rest of the system.

This modularity significantly accelerates adversarial robustness research and deployment. In particular, it enables easy adaptation of ALU-based defense strategies to varying architectural, purification, and detection frameworks. A plausible implication is that such functional decomposition may serve as a template for constructing similarly modular defense systems beyond the logit-based paradigm [2308.15072].

## 6. Summary and Research Context

Currying ALU provides an elegant methodology for modularizing adversarial logit update classification, yielding clear separation of classifier, purification, and decision logic. This strongly supports systematic investigation of purification strategies and classifier architectures in adversarial defense. Currying the ALU function leads to improved software reusability and facilitates robust performance across different attack scenarios, as substantiated in the empirical findings on CIFAR-10, CIFAR-100, and tiny-ImageNet datasets [2308.15072]. The curricular, functional formulation and its modular ramifications represent a distinctive contribution to the adversarial robustness literature.

Source: https://www.emergentmind.com/topics/currying-alu