paper-with-me

Papers

Interpreting Adversarial Robustness: A View from Decision Surface in Input Space

2018-09-29 · ICLR 2019 5 · Fuxun Yu, ChenChen Liu, Yanzhi Wang, Liang Zhao, Xiang Chen

One popular hypothesis of neural network generalization is that the flat local minima of loss surface in parameter space leads to good generalization. However, we demonstrate that loss surface in parameter space has no obvious relationship with generalization, especially under adversarial settings. Through visualizing decision surfaces in both parameter space and input space, we instead show that the geometry property of decision surface in input space correlates well with the adversarial robustness. We then propose an adversarial robustness indicator, which can evaluate a neural network's intrinsic robustness property without testing its accuracy under adversarial attacks. Guided by it, we further propose our robust training method. Without involving adversarial training, our method could enhance network's intrinsic adversarial robustness against various adversarial attacks.

📄 PDF Abstract BibTeX arXiv:1810.00144

Code (0)

등록된 구현이 없습니다.

Tasks

Adversarial Robustness

Similar Papers 제목 키워드 기반

On Visual Hallmarks of Robustness to Adversarial Malware

2018-05-09 · Alex Huang, Abdullah Al-Dujaili, Erik Hemberg, Una-May O'Reilly

A central challenge of adversarial learning is to interpret the resulting hardened model. In this contribution, we ask how robust generalization can be visually discerned and whether a concise view of the interactions be…

Adversarial Robustness via Adaptive Label Smoothing

2021-09-29 · Qibing Ren, Liangliang Shi, Lanjun Wang, Junchi Yan

Adversarial training (AT) has become a dominant defense paradigm by enforcing the model's predictions to be locally invariant to adversarial examples. Being a simple technique, Label smoothing (LS) has shown its potentia…

Adversarial Robustness

Robustness via curvature regularization, and vice versa

2018-11-23 · CVPR 2019 6 · Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Jonathan Uesato, Pascal Frossard

State-of-the-art classifiers have been shown to be largely vulnerable to adversarial perturbations. One of the most effective strategies to improve robustness is adversarial training. In this paper, we investigate the ef…

Adversarial Robustness

Improving Robustness against Real-World and Worst-Case Distribution Shifts through Decision Region Quantification

2022-05-19 · Leo Schwinn, Leon Bungert, An Nguyen, René Raab 외

The reliability of neural networks is essential for their use in safety-critical applications. Existing approaches generally aim at improving the robustness of neural networks to either real-world distribution shifts (e.…

Interpreting Adversarial Examples with Attributes

2019-04-17 · Sadaf Gulshad, Jan Hendrik Metzen, Arnold Smeulders, Zeynep Akata

Deep computer vision systems being vulnerable to imperceptible and carefully crafted noise have raised questions regarding the robustness of their decisions. We take a step back and approach this problem from an orthogon…

AttributeGeneral Classification