paper-with-me

Papers

Where Does the Robustness Come from? A Study of the Transformation-based Ensemble Defence

2020-09-28 · Chang Liao, Yao Cheng, Chengfang Fang, Jie Shi

This paper aims to provide a thorough study on the effectiveness of the transformation-based ensemble defence for image classification and its reasons. It has been empirically shown that they can enhance the robustness against evasion attacks, while there is little analysis on the reasons. In particular, it is not clear whether the robustness improvement is a result of transformation or ensemble. In this paper, we design two adaptive attacks to better evaluate the transformation-based ensemble defence. We conduct experiments to show that 1) the transferability of adversarial examples exists among the models trained on data records after different reversible transformations; 2) the robustness gained through transformation-based ensemble is limited; 3) this limited robustness is mainly from the irreversible transformations rather than the ensemble of a number of models; and 4) blindly increasing the number of sub-models in a transformation-based ensemble does not bring extra robustness gain.

📄 PDF Abstract BibTeX arXiv:2009.13033

Code (0)

등록된 구현이 없습니다.

Tasks

image-classificationImage Classification

Similar Papers 제목 키워드 기반

Does ESG and Digital Transformation affects Corporate Sustainability? The Moderating role of Green Innovation

2023-11-30 · Chenglin Qing, Shanyue Jin

Recently, environmental, social, and governance (ESG) has become an important factor in companies' sustainable development. Artificial intelligence (AI) is also a core digital technology that can create innovative, susta…

Management

Enhancing Adversarial Robustness via Test-time Transformation Ensembling

2021-07-29 · Juan C. Pérez, Motasem Alfarra, Guillaume Jeanneret, Laura Rueda 외

Deep learning models are prone to being fooled by imperceptible perturbations known as adversarial attacks. In this work, we study how equipping models with Test-time Transformation Ensembling (TTE) can work as a reliabl…

Adversarial Robustness

Aligning Partially Overlapping Point Sets: an Inner Approximation Algorithm

2020-07-05 · Wei Lian, WangMeng Zuo, Lei Zhang

Aligning partially overlapping point sets where there is no prior information about the value of the transformation is a challenging problem in computer vision. To achieve this goal, we first reduce the objective of the …

From Robustness to Privacy and Back

2023-02-03 · Hilal Asi, Jonathan Ullman, Lydia Zakynthinou

We study the relationship between two desiderata of algorithms in statistical inference and machine learning: differential privacy and robustness to adversarial data corruptions. Their conceptual similarity was first obs…

Deep Transformation-Invariant Clustering

2020-06-19 · NeurIPS 2020 12 · Tom Monnier, Thibault Groueix, Mathieu Aubry

Recent advances in image clustering typically focus on learning better deep representations. In contrast, we present an orthogonal approach that does not rely on abstract features but instead learns to predict image tran…

ClusteringImage ClusteringUnsupervised Image Classification