paper-with-me

홈 › Papers

Adversarial Training with Voronoi Constraints

2019-05-02 · Marc Khoury, Dylan Hadfield-Menell

Adversarial examples are a pervasive phenomenon of machine learning models where seemingly imperceptible perturbations to the input lead to misclassifications for otherwise statistically accurate models. We propose a geometric framework, drawing on tools from the manifold reconstruction literature, to analyze the high-dimensional geometry of adversarial examples. In particular, we highlight the importance of codimension: for low-dimensional data manifolds embedded in high-dimensional space there are many directions off the manifold in which an adversary could construct adversarial examples. Adversarial examples are a natural consequence of learning a decision boundary that classifies the low-dimensional data manifold well, but classifies points near the manifold incorrectly. Using our geometric framework we prove that adversarial training is sample inefficient, and show sufficient sampling conditions under which nearest neighbor classifiers and ball-based adversarial training are robust. Finally we introduce adversarial training with Voronoi constraints, which replaces the norm ball constraint with the Voronoi cell for each point in the training set. We show that adversarial training with Voronoi constraints produces robust models which significantly improve over the state-of-the-art on MNIST and are competitive on CIFAR-10.

📄 PDF Abstract BibTeX arXiv:1905.01019

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Measuring Adversarial Robustness using a Voronoi-Epsilon Adversary

2020-05-06 · Hyeongji Kim, Pekka Parviainen, Ketil Malde

Previous studies on robustness have argued that there is a tradeoff between accuracy and adversarial accuracy. The tradeoff can be inevitable even when we neglect generalization. We argue that the tradeoff is inherent to…

Adversarial Robustness

Adversarial Examples for $k$-Nearest Neighbor Classifiers Based on Higher-Order Voronoi Diagrams

2020-11-19 · NeurIPS 2021 12 · Chawin Sitawarin, Evgenios M. Kornaropoulos, Dawn Song, David Wagner

Adversarial examples are a widely studied phenomenon in machine learning models. While most of the attention has been focused on neural networks, other practical models also suffer from this issue. In this work, we propo…

Adversarial Robustness

Adversarial Examples for k-Nearest Neighbor Classifiers Based on Higher-Order Voronoi Diagrams

2021-05-21 · NeurIPS 2021 12 · Chawin Sitawarin, Evgenios M. Kornaropoulos, Dawn Song, David Wagner

Adversarial examples are a widely studied phenomenon in machine learning models. While most of the attention has been focused on neural networks, other practical models also suffer from this issue. In this work, we propo…

Adversarial Robustness

Dynamical system prediction from sparse observations using deep neural networks with Voronoi tessellation and physics constraint

2024-08-31 · HanYang Wang, Hao Zhou, Sibo Cheng

Despite the success of various methods in addressing the issue of spatial reconstruction of dynamical systems with sparse observations, spatio-temporal prediction for sparse fields remains a challenge. Existing Kriging-b…

Computational EfficiencyPredictionTime Series Prediction

Structured Adversarial Camouflage via Voronoi Diagrams

2026-06-16 · Jens Bayer, Stefan Becker, David Münch, Michael Arens 외 arxiv

Pixel-wise adversarial patches are computationally heavy and often visually detectable, limiting utility in security-critical systems. We present adversarial Voronoi camouflage that optimizes only seed-point locations un…