paper-with-me

Papers

Golyadkin's Torment: Doppelgängers and Adversarial Vulnerability

2024-10-17 · George I. Kamberov

Many machine learning (ML) classifiers are claimed to outperform humans, but they still make mistakes that humans do not. The most notorious examples of such mistakes are adversarial visual metamers. This paper aims to define and investigate the phenomenon of adversarial Doppelgangers (AD), which includes adversarial visual metamers, and to compare the performance and robustness of ML classifiers to human performance. We find that AD are inputs that are close to each other with respect to a perceptual metric defined in this paper. AD are qualitatively different from the usual adversarial examples. The vast majority of classifiers are vulnerable to AD and robustness-accuracy trade-offs may not improve them. Some classification problems may not admit any AD robust classifiers because the underlying classes are ambiguous. We provide criteria that can be used to determine whether a classification problem is well defined or not; describe the structure and attributes of an AD-robust classifier; introduce and explore the notions of conceptual entropy and regions of conceptual ambiguity for classifiers that are vulnerable to AD attacks, along with methods to bound the AD fooling rate of an attack. We define the notion of classifiers that exhibit hypersensitive behavior, that is, classifiers whose only mistakes are adversarial Doppelgangers. Improving the AD robustness of hyper-sensitive classifiers is equivalent to improving accuracy. We identify conditions guaranteeing that all classifiers with sufficiently high accuracy are hyper-sensitive. Our findings are aimed at significant improvements in the reliability and security of machine learning systems.

📄 PDF Abstract BibTeX arXiv:2410.13193

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Doppelgangers and Adversarial Vulnerability

2025-01-01 · CVPR 2025 1 · George Kamberov

Many machine learning (ML) classifiers are claimed to outperform humans, but they still make mistakes that humans do not. The most notorious examples of such mistakes are adversarial visual metamers. This paper aims …

Reliable Detection of Doppelgängers based on Deep Face Representations

2022-01-21 · Christian Rathgeb, Daniel Fischer, Pawel Drozdowski, Christoph Busch

Doppelg\"angers (or lookalikes) usually yield an increased probability of false matches in a facial recognition system, as opposed to random face image pairs selected for non-mated comparison trials. In this work, we ass…

Face Recognition

Doppelgangers++: Improved Visual Disambiguation with Geometric 3D Features

2024-12-08 · CVPR 2025 1 · Yuanbo Xiangli, Ruojin Cai, HanYu Chen, Jeffrey Byrne 외

Accurate 3D reconstruction is frequently hindered by visual aliasing, where visually similar but distinct surfaces (aka, doppelgangers), are incorrectly matched. These spurious matches distort the structure-from-motion (…

3D Reconstruction

Doppelganger Method: Breaking Role Consistency in LLM Agent via Prompt-based Transferable Adversarial Attack

2025-06-17 · Daewon Kang, YeongHwan Shin, Doyeon Kim, Kyu-Hwan Jung 외

Since the advent of large language models, prompt engineering now enables the rapid, low-effort creation of diverse autonomous agents that are already in widespread use. Yet this convenience raises urgent concerns about …

Adversarial AttackPrompt Engineering

Doppelgangers: Learning to Disambiguate Images of Similar Structures

2023-09-05 · ICCV 2023 1 · Ruojin Cai, Joseph Tung, Qianqian Wang, Hadar Averbuch-Elor 외

We consider the visual disambiguation task of determining whether a pair of visually similar images depict the same or distinct 3D surfaces (e.g., the same or opposite sides of a symmetric building). Illusory image match…

3D ReconstructionBinary Classification