arXiv · 2509.22755
Concept activation vectors: a unifying view and adversarial attacks
Abstract
Concept Activation Vectors (CAVs) are a tool from explainable AI, offering a promising approach for understanding how human-understandable concepts are encoded in a model's latent spaces. They are computed from hidden-layer activations of inputs belonging either to a concept class or to non-concept examples. Adopting a probabilistic perspective, the distribution of the (non-)concept inputs induces a distribution over the CAV, making it a random vector in the latent space. This enables us to derive mean and covariance for different types of CAVs, leading to a unified theoretical view. This probabilistic perspective also reveals a potential vulnerability: CAVs can strongly depend on the rather arbitrary non-concept distribution, a factor largely overlooked in prior work. We illustrate this with a simple yet effective adversarial attack, underscoring the need for a more systematic study.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Ekkehard Schnoor, Malik Tiomoko, Jawher Said, Alex Jung, Wojciech Samek. 2025-09-26. Concept activation vectors: a unifying view and adversarial attacks. https://arxiv.org/abs/2509.22755
Cite the original work for its findings. Save a collection to share your selection of sources.