The Limitations of Model Uncertainty in Adversarial Settings
Machine learning models are vulnerable to adversarial examples: minor perturbations to input samples intended to deliberately cause misclassification. While an obvious security threat, adversarial examples yield as well insights about the applied model itself. We investigate adversarial examples in the context of Bayesian neural network's (BNN's) uncertainty measures. As these measures are highly non-smooth, we use a smooth Gaussian process classifier (GPC) as substitute. We show that both confidence and uncertainty can be unsuspicious even if the output is wrong. Intriguingly, we find subtle differences in the features influencing uncertainty and confidence for most tasks.
Code (0)
등록된 구현이 없습니다.
Tasks
BIG-bench Machine LearningGaussian ProcessesmodelMethods 이 논문이 사용한 방법론
Similar Papers 제목 키워드 기반
How Wrong Am I? - Studying Adversarial Examples and their Impact on Uncertainty in Gaussian Process Machine Learning Models
Machine learning models are vulnerable to Adversarial Examples: minor perturbations to input samples intended to deliberately cause misclassification. Current defenses against adversarial examples, especially for Deep Ne…
Bayesian InferenceGaussian ProcessesRobustness Meets Uncertainty: Evidential Adversarial Training for Robust Selective Classification
Safety-critical applications require classifiers that are both robust and reliable. Adversarial training is a widely adopted defense for improving robustness in deep neural networks; however, its effect on the reliabilit…
Adversarial RobustnessMulti-head Uncertainty Inference for Adversarial Attack Detection
Deep neural networks (DNNs) are sensitive and susceptible to tiny perturbation by adversarial attacks which causes erroneous predictions. Various methods, including adversarial defense and uncertainty inference (UI), hav…
Adversarial AttackAdversarial Attack DetectionAdversarial DefenseSuccess of Uncertainty-Aware Deep Models Depends on Data Manifold Geometry
For responsible decision making in safety-critical settings, machine learning models must effectively detect and process edge-case data. Although existing works show that predictive uncertainty is useful for these tasks,…
Decision MakingDeep LearningUncertainty-Guided Selective Adaptation Enables Cross-Platform Predictive Fluorescence Microscopy
Deep learning is transforming microscopy, yet models often fail when applied to images from new instruments or acquisition settings. Conventional adversarial domain adaptation (ADDA) retrains entire networks, often disru…
Domain Adaptation