Understanding Intrinsic Robustness Using Label Uncertainty
Xiao Zhang, David E. Evans
Abstract
A fundamental question in adversarial machine learning is whether a robust classifier exists for a given task. A line of research has made some progress towards this goal by studying the concentration of measure, but we argue standard concentration fails to fully characterize the intrinsic robustness of a classification problem since it ignores data labels which are essential to any classification task. Building on a novel definition of label uncertainty, we empirically demonstrate that error regions induced by state-of-the-art models tend to have much higher label uncertainty than randomly-selected subsets. This observation motivates us to adapt a concentration estimation algorithm to account for label uncertainty, resulting in more accurate intrinsic robustness measures for benchmark image classification problems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- MalCertain: Enhancing Deep Neural Network Based Android Malware Detection by Tackling Prediction UncertaintyHaodong Li, Guosheng Xu, Liu Wang, Xusheng Xiao et al.ICSE 2024 · 17 citations
- Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial RobustnessAmbar Pal, Jeremias Sulam, René VidalNeurIPS 2023 · 15 citations
- How to Enable Effective Cooperation Between Humans and NLP Models: A Survey of Principles, Formalizations, and BeyondChen Huang, Yang Deng, Wenqiang Lei, Jiancheng Lv et al.ACL 2025
Builds on9
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 917 citations
- Towards Stable and Efficient Training of Verifiably Robust Neural NetworksHuan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal et al.ICLR 2020 · 384 citations
Related papers
- Improved Estimation of Concentration Under ℓp-Norm Distance Metrics Using Half SpacesJack Prescott, Xiao Zhang, David E. EvansICLR 2021 · 5 citations
- Beyond Categorical Label Representations for Image ClassificationBoyuan Chen, Yu Li, Sunand Raghupathi, Hod LipsonICLR 2021
- On the Error Resistance of Hinge-Loss MinimizationKunal TalwarNeurIPS 2020 · 7 citations
- Human Uncertainty Makes Classification More RobustJoshua C. Peterson, Ruairidh M. Battleday, Thomas L. Griffiths, Olga RussakovskyICCV 2019 · 362 citations
- Combating Noise: Semi-supervised Learning by Region Uncertainty QuantificationZhenyu Wang, Ya-Li Li, Ye Guo, Shengjin WangNeurIPS 2021 · 34 citations
