Adversarial robustness of amortized Bayesian inference
Manuel Glöckler, Michael Deistler, Jakob H. Macke
Abstract
Bayesian inference usually requires running potentially costly inference procedures separately for every new observation. In contrast, the idea of amortized Bayesian inference is to initially invest computational cost in training an inference network on simulated data, which can subsequently be used to rapidly perform inference (i.e., to return estimates of posterior distributions) for new observations. This approach has been applied to many real-world models in the sciences and engineering, but it is unclear how robust the approach is to adversarial perturbations in the observed data. Here, we study the adversarial robustness of amortized Bayesian inference, focusing on simulation-based estimation of multi-dimensional posterior distributions. We show that almost unrecognizable, targeted perturbations of the observations can lead to drastic changes in the predicted posterior and highly unrealistic posterior predictive samples, across several benchmark tasks and a real-world example from neuroscience. We propose a computationally efficient regularization scheme based on penalizing the Fisher information of the conditional density estimator, and show how it improves the adversarial robustness of amortized Bayesian inference.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Effortless, Simulation-Efficient Bayesian Inference using Tabular Foundation ModelsJulius Vetter, Manuel Glöckler, Daniel Gedon, Jakob H. MackeNeurIPS 2025 · 14 citations
- Rethinking Adversarial Robustness in the Context of the Right to be ForgottenChenxu Zhao, Wei Qian, Yangyi Li, Aobo Chen et al.ICML 2024 · 12 citations
- Sourcerer: Sample-based Maximum Entropy Source Distribution EstimationJulius Vetter, Guy Moss, Cornelius Schröder, Richard Gao et al.NeurIPS 2024 · 11 citations
- Compositional simulation-based inference for time seriesManuel Glöckler, Shoji Toyota, Kenji Fukumizu, Jakob H. MackeICLR 2025
- Robust Simulation-Based Inference under Missing Data via Neural ProcessesYogesh Verma, Ayush Bharti, Vikas GargICLR 2025
Builds on7
- Likelihood-free MCMC with Amortized Approximate Ratio EstimatorsJoeri Hermans, Volodimir Begy, Gilles LouppeICML 2020 · 246 citations
- Robust Neural Posterior Estimation and Statistical Model CriticismDaniel Ward, Patrick Cannon, Mark Beaumont, Matteo Fasiolo et al.NeurIPS 2022 · 79 citations
- Truncated proposals for scalable and hassle-free simulation-based inferenceMichael Deistler, Pedro J. Gonçalves, Jakob H. MackeNeurIPS 2022 · 76 citations
- Improving VAEs' Robustness to Adversarial AttackMatthew Willetts, Alexander Camuto, Tom Rainforth, Stephen J. Roberts et al.ICLR 2021 · 30 citations
- Adversarial Attacks on Probabilistic Autoregressive Forecasting ModelsRaphaël Dang-Nhu, Gagandeep Singh, Pavol Bielik, Martin T. VechevICML 2020 · 28 citations
Related papers
- Multifidelity Simulation-based Inference for Computationally Expensive SimulatorsAnastasia Nastya Krouglova, Hayden R. Johnson, Basile Confavreux, Michael Deistler et al.ICLR 2026 · 17 citations
- Minimum Distance Summaries for Robust Neural Posterior EstimationSherman Khoo, Dennis Prangle, Song Liu, Mark BeaumontICML 2026 · 2 citations
- Generalized Bayesian Inference for Scientific Simulators via Amortized Cost EstimationRichard Gao, Michael Deistler, Jakob H. MackeNeurIPS 2023 · 19 citations
- All-in-one simulation-based inferenceManuel Glöckler, Michael Deistler, Christian Dietrich Weilbach, Frank Wood et al.ICML 2024 · 74 citations
- Robust Amortized Bayesian Inference with Self-Consistency Losses on Unlabeled DataAayush Mishra, Daniel Habermann, Marvin Schmitt, Stefan T. Radev et al.ICLR 2026 · 14 citations
