# Explaining Adversarial Examples by Local Properties of Convolutional Neural Networks

### Hamed H. Aghdam, Elnaz J. Heravi, Domenec Puig

#### Abstract

Vulnerability of ConvNets to adversarial examples have been mainly studied by devising a solution for generating adversarial examples. Early studies suggested that sensitivity of ConvNets to adversarial examples are due to their non-linearity. Most recent studies explained that instability of ConvNet to these examples are because of their linear nature. In this work, we analyze some of local properties of ConvNets that are directly related to their unreliability to adversarial examples. We shows that ConvNets are not locally isotropic and symmetric. Also, we show that Mantel score of distance matrices in the input and output of a ConvNet is very low showing that topology of points located at a very close distance to a samples might significantly change by ConvNets. We also explain that non-linearity of topology changes in ConvNet are because they apply an affine transformation in each layer. Furthermore, we explain that despite the fact that global Lipschitz constant of a ConvNet might be greater than 1, it is locally less than 1 in most of adversarial examples.

