Adversarially Robust Representations with Smooth Encoders
A. Taylan Cemgil, Sumedh Ghaisas, Krishnamurthy (Dj) Dvijotham, Pushmeet Kohli
Abstract
This paper studies the undesired phenomena of over-sensitivity of representations learned by deep networks to semantically-irrelevant changes in data. We identify a cause for this shortcoming in the classical Variational Auto-encoder (VAE) objective, the evidence lower bound (ELBO). We show that the ELBO fails to control the behaviour of the encoder out of the support of the empirical data distribution and this behaviour of the VAE can lead to extreme errors in the learned representation. This is a key hurdle in the effective use of representations for data-efficient learning and transfer. To address this problem, we propose to augment the data with specifications that enforce insensitivity of the representation with respect to families of transformations. To incorporate these specifications, we propose a regularization method that is based on a selection mechanism that creates a fictive data point by explicitly perturbing an observed true data point. For certain choices of parameters, our formulation naturally leads to the minimization of the entropy regularized Wasserstein distance between representations. We illustrate our approach on standard datasets and experimentally show that significant improvements in the downstream adversarial accuracy can be achieved by learning robust representations completely in an unsupervised manner, without a reference to a particular downstream task and without a costly supervised adversarial training procedure.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- The Autoencoding Variational AutoencoderA. Taylan Cemgil, Sumedh Ghaisas, Krishnamurthy Dvijotham, Sven Gowal et al.NeurIPS 2020 · 81 citations
- Exploring the Latent Space of Autoencoders with Interventional AssaysFelix Leeb, Stefan Bauer, Michel Besserve, Bernhard SchölkopfNeurIPS 2022 · 26 citations
- Improving Model Robustness by Adaptively Correcting Perturbation Levels with Active QueriesKun-Peng Ning, Lue Tao, Songcan Chen, Sheng-Jun HuangAAAI 2021 · 17 citations
- Alleviating Adversarial Attacks on Variational Autoencoders with MCMCAnna Kuzina, Max Welling, Jakub M. TomczakNeurIPS 2022 · 16 citations
- Adversarial Examples Can Be Effective Data Augmentation for Unsupervised Machine LearningChia-Yi Hsu, Pin-Yu Chen, Songtao Lu, Sijia Liu et al.AAAI 2022 · 13 citations
Related papers
- Consistency Regularization for Variational Auto-EncodersSamarth Sinha, Adji Bousso DiengNeurIPS 2021 · 83 citations
- Maximum-Entropy Adversarial Data Augmentation for Improved Generalization and RobustnessLong Zhao, Ting Liu, Xi Peng, Dimitris N. MetaxasNeurIPS 2020 · 207 citations
- Improving VAEs' Robustness to Adversarial AttackMatthew Willetts, Alexander Camuto, Tom Rainforth, Stephen J. Roberts et al.ICLR 2021 · 30 citations
- Trading off Image Quality for Robustness is not Necessary with Regularized Deterministic AutoencodersAmrutha Saseendran, Kathrin Skubch, Stefan Falkner, Margret KeuperNeurIPS 2022
- BooVAE: Boosting Approach for Continual Learning of VAEEvgenii Egorov, Anna Kuzina, Evgeny BurnaevNeurIPS 2021 · 34 citations
