Robustness between the worst and average case
Leslie Rice, Anna Bair, Huan Zhang, J. Zico Kolter
Abstract
Several recent works in machine learning have focused on evaluating the test-time robustness of a classifier: how well the classifier performs not just on the target domain it was trained upon, but upon perturbed examples. In these settings, the focus has largely been on two extremes of robustness: the robustness to perturbations drawn at random from within some distribution (i.e., robustness to random perturbations), and the robustness to the worst case perturbation in some set (i.e., adversarial robustness). In this paper, we argue that a sliding scale between these two extremes provides a valuable additional metric by which to gauge robustness. Specifically, we illustrate that each of these two extremes is naturally characterized by a (functional) q-norm over perturbation space, with q = 1 corresponding to robustness to random perturbations and q = 1 corresponding to adversarial perturbations. We then present the main technical contribution of our paper: a method for efficiently estimating the value of these norms by interpreting them as the partition function of a particular distribution, then using path sampling with MCMC methods to estimate this partition function (either traditional Metropolis-Hastings for non-differentiable perturbations, or Hamiltonian Monte Carlo for differentiable perturbations). We show that our approach provides substantially better estimates than simple random sampling of the actual "intermediate-q" robustness of standard, data-augmented, and adversarially-trained classifiers, illustrating a clear tradeoff between classifiers that optimize different metrics. Code for reproducing experiments can be found at https://github.com/locuslab/intermediate_robustness .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6a286b2d-88b4-42b3-9dee-0403e88297e6Cited by top-tier papers12
- Probable Domain Generalization via Quantile Risk MinimizationCian Eastwood, Alexander Robey, Shashank Singh, Julius von Kügelgen et al.NeurIPS 2022 · 99 citations
- Probabilistically Robust Learning: Balancing Average and Worst-case PerformanceAlexander Robey, Luiz F. O. Chamon, George J. Pappas, Hamed HassaniICML 2022 · 50 citations
- Robustness Implies Generalization via Data-Dependent Generalization BoundsKenji Kawaguchi, Zhun Deng, Kyle Luh, Jiaoyang HuangICML 2022 · 28 citations
- Bounding the Expected Robustness of Graph Neural Networks Subject to Node Feature AttacksYassine Abbahaddou, Sofiane Ennadir, Johannes F. Lutzeyer, Michalis Vazirgiannis et al.ICLR 2024 · 15 citations
- If You Want to Be Robust, Be Wary of InitializationSofiane Ennadir, Johannes F. Lutzeyer, Michalis Vazirgiannis, El Houcine BergouNeurIPS 2024 · 5 citations
Builds on6
- The Many Faces of Robustness: A Critical Analysis of Out-of-Distribution GeneralizationDan Hendrycks, Steven Basart, Norman Mu, Saurav Kadavath et al.ICCV 2021 · 2,294 citations
- AugMix: A Simple Data Processing Method to Improve Robustness and UncertaintyDan Hendrycks, Norman Mu, Ekin Dogus Cubuk, Barret Zoph et al.ICLR 2020 · 1,572 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Measuring Robustness to Natural Distribution Shifts in Image ClassificationRohan Taori, Achal Dave, Vaishaal Shankar, Nicholas Carlini et al.NeurIPS 2020 · 731 citations
- Learning perturbation sets for robust machine learningEric Wong, J. Zico KolterICLR 2021 · 40 citations
Related papers
- MEMO: Test Time Robustness via Adaptation and AugmentationMarvin Zhang, Sergey Levine, Chelsea FinnNeurIPS 2022 · 595 citations
- Quantification of Uncertainty with Adversarial ModelsKajetan Schweighofer, Lukas Aichberger, Mykyta Ielanskyi, Günter Klambauer et al.NeurIPS 2023 · 37 citations
- Treatment of Statistical Estimation Problems in Randomized Smoothing for Adversarial RobustnessVáclav VorácekNeurIPS 2024 · 12 citations
- DRF: Improving Certified Robustness via Distributional Robustness FrameworkZekai Wang, Zhengyu Zhou, Weiwei LiuAAAI 2024 · 7 citations
- Adversarial Robustness with Semi-Infinite Constrained LearningAlexander Robey, Luiz F. O. Chamon, George J. Pappas, Hamed Hassani et al.NeurIPS 2021 · 51 citations
