paper-with-me

홈 › Papers

Detecting Brittle Decisions for Free: Leveraging Margin Consistency in Deep Robust Classifiers

2024-06-26 · Jonas Ngnawé, Sabyasachi Sahoo, Yann Pequignot, Frédéric Precioso, Christian Gagné

Despite extensive research on adversarial training strategies to improve robustness, the decisions of even the most robust deep learning models can still be quite sensitive to imperceptible perturbations, creating serious risks when deploying them for high-stakes real-world applications. While detecting such cases may be critical, evaluating a model's vulnerability at a per-instance level using adversarial attacks is computationally too intensive and unsuitable for real-time deployment scenarios. The input space margin is the exact score to detect non-robust samples and is intractable for deep neural networks. This paper introduces the concept of margin consistency -- a property that links the input space margins and the logit margins in robust models -- for efficient detection of vulnerable samples. First, we establish that margin consistency is a necessary and sufficient condition to use a model's logit margin as a score for identifying non-robust samples. Next, through comprehensive empirical analysis of various robustly trained models on CIFAR10 and CIFAR100 datasets, we show that they indicate high margin consistency with a strong correlation between their input space margins and the logit margins. Then, we show that we can effectively and confidently use the logit margin to detect brittle decisions with such models. Finally, we address cases where the model is not sufficiently margin-consistent by learning a pseudo-margin from the feature representation. Our findings highlight the potential of leveraging deep representations to assess adversarial vulnerability in deployment scenarios efficiently.

📄 PDF Abstract BibTeX arXiv:2406.18451

Code (1)

ngnawejonas/margin-consistency 공식 구현 pytorch

Methods 이 논문이 사용한 방법론

SET Dynamic Sparse Training method where weight mask is updated randomly periodically

Similar Papers 제목 키워드 기반

Informative Outlier Matters: Robustifying Out-of-distribution Detection Using Outlier Mining

2020-09-28 · Jiefeng Chen, Yixuan Li, Xi Wu, YIngyu Liang 외

Detecting out-of-distribution (OOD) inputs is critical for safely deploying deep learning models in an open-world setting. However, existing OOD detection solutions can be brittle in the open world, facing various types …

Out-of-Distribution DetectionOut of Distribution (OOD) Detection

ATOM: Robustifying Out-of-distribution Detection Using Outlier Mining

2020-06-26 · Jiefeng Chen, Yixuan Li, Xi Wu, YIngyu Liang 외

Detecting out-of-distribution (OOD) inputs is critical for safely deploying deep learning models in an open-world setting. However, existing OOD detection solutions can be brittle in the open world, facing various types …

Out-of-Distribution DetectionOut of Distribution (OOD) Detection

Extractive Summarization of Legal Decisions using Multi-task Learning and Maximal Marginal Relevance

2022-10-22 · Abhishek Agarwal, Shanshan Xu, Matthias Grabmair

Summarizing legal decisions requires the expertise of law practitioners, which is both time- and cost-intensive. This paper presents techniques for extractive summarization of legal decisions in a low-resource setting us…

Extractive SummarizationMulti-Task Learning

Conformalized Decision Risk Assessment

2025-05-19 · Wenbin Zhou, Agni Orfanoudaki, Shixiang Zhu

High-stakes decisions in domains such as healthcare, energy, and public policy are often made by human experts using domain knowledge and heuristics, yet are increasingly supported by predictive and optimization-based to…

Conformal Prediction

Which Decisions Low-Bit Quantization Breaks, and How to Predict Them

2026-08-06 · Zekun Wu, Swati Dhiman, Adriano Koshiyama arxiv

Quantization is known to hurt below four bits, but nobody can say which of a model's decisions will change at a given bit-width. This matters most where a model acts rather than answers: a compressed agent stops calling …