Defense Through Diverse Directions
Christopher M. Bender, Yang Li, Yifeng Shi, Michael K. Reiter, Junier Oliva
Abstract
In this work we develop a novel Bayesian neural network methodology to achieve strong adversarial robustness without the need for online adversarial training. Unlike previous efforts in this direction, we do not rely solely on the stochasticity of network weights by minimizing the divergence between the learned parameter distribution and a prior. Instead, we additionally require that the model maintain some expected uncertainty with respect to all input covariates. We demonstrate that by encouraging the network to distribute evenly across inputs, the network becomes less susceptible to localized, brittle features which imparts a natural robustness to targeted perturbations. We show empirical robustness on several benchmark datasets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1e7f94bf-5ed4-413e-93b5-2b0b7f5ece8fCited by top-tier papers2
- Demystifying the Adversarial Robustness of Random Transformation DefensesChawin Sitawarin, Zachary J. Golan-Strieb, David A. WagnerICML 2022 · 26 citations
- How Sampling Impacts the Robustness of Stochastic Neural NetworksSina Däubener, Asja FischerNeurIPS 2022 · 1 citation
Builds on1
Related papers
- Encoding Robustness to Image Style via Adversarial Feature PerturbationsManli Shu, Zuxuan Wu, Micah Goldblum, Tom GoldsteinNeurIPS 2021 · 23 citations
- Robust Bayesian Neural Networks by Spectral Expectation Bound RegularizationJiaru Zhang, Yang Hua, Zhengui Xue, Tao Song et al.CVPR 2021
- Robustness to corruption in pre-trained Bayesian neural networksXi Wang, Laurence AitchisonICLR 2023
- Quantifying Uncertainty in the Presence of Distribution ShiftsYuli Slavutsky, David M. BleiNeurIPS 2025 · 2 citations
- Dangers of Bayesian Model Averaging under Covariate ShiftPavel Izmailov, Patrick Nicholson, Sanae Lotfi, Andrew Gordon WilsonNeurIPS 2021 · 51 citations
