paper-with-me

Papers

Doppelgangers and Adversarial Vulnerability

2025-01-01 · CVPR 2025 1 · George Kamberov

Many machine learning (ML) classifiers are claimed to outperform humans, but they still make mistakes that humans do not. The most notorious examples of such mistakes are adversarial visual metamers. This paper aims to define and investigate the phenomenon of adversarial Doppelgangers (AD), which includes adversarial visual metamers, and to compare the performance and robustness of ML classifiers to human performance.We find that AD are inputs that are close to each other with respect to a perceptual metric defined in this paper, and show that AD are qualitatively different from the usual adversarial examples. The vast majority of classifiers are vulnerable to AD and robustness-accuracy trade-offs may not improve them. Some classification problems may not admit any AD robust classifiers because the underlying classes are ambiguous. We provide criteria that can be used to determine whether a classification problem is well defined or not; describe of an AD robust classifiers' structure and attributes; introduce and explore the notions of conceptual entropy and regions of conceptual ambiguity for classifiers that are vulnerable to AD attacks, along with methods to bound the AD fooling rate of an attack. We define the notion of classifiers that exhibit hyper-sensitive behavior, that is, classifiers whose only mistakes are adversarial Doppelgangers. Improving the AD robustness of hyper-sensitive classifiers proving accuracy. We identify conditions guaranteeing that all classifiers with sufficiently high accuracy are hyper-sensitive.

📄 PDF Abstract BibTeX

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Golyadkin's Torment: Doppelgängers and Adversarial Vulnerability

2024-10-17 · George I. Kamberov

Many machine learning (ML) classifiers are claimed to outperform humans, but they still make mistakes that humans do not. The most notorious examples of such mistakes are adversarial visual metamers. This paper aims to d…

Doppelgangers++: Improved Visual Disambiguation with Geometric 3D Features

2024-12-08 · CVPR 2025 1 · Yuanbo Xiangli, Ruojin Cai, HanYu Chen, Jeffrey Byrne 외

Accurate 3D reconstruction is frequently hindered by visual aliasing, where visually similar but distinct surfaces (aka, doppelgangers), are incorrectly matched. These spurious matches distort the structure-from-motion (…

3D Reconstruction

Doppelgangers: Learning to Disambiguate Images of Similar Structures

2023-09-05 · ICCV 2023 1 · Ruojin Cai, Joseph Tung, Qianqian Wang, Hadar Averbuch-Elor 외

We consider the visual disambiguation task of determining whether a pair of visually similar images depict the same or distinct 3D surfaces (e.g., the same or opposite sides of a symmetric building). Illusory image match…

3D ReconstructionBinary Classification

Adversarial Neural Pruning with Latent Vulnerability Suppression

2019-08-12 · ICML 2020 1 · Divyam Madaan, Jinwoo Shin, Sung Ju Hwang

Despite the remarkable performance of deep neural networks on various computer vision tasks, they are known to be susceptible to adversarial perturbations, which makes it challenging to deploy them in real-world safety-c…

Adversarial Robustness

Enhancing Neural Models with Vulnerability via Adversarial Attack

2020-12-01 · COLING 2020 8 · Rong Zhang, Qifei Zhou, Bo An, Weiping Li 외

Natural Language Sentence Matching (NLSM) serves as the core of many natural language processing tasks. 1) Most previous work develops a single specific neural model for NLSM tasks. 2) There is no previous work consideri…

Adversarial AttackSentence