Disrupting Deep Uncertainty Estimation Without Harming Accuracy
Ido Galil, Ran El-Yaniv
Abstract
Deep neural networks (DNNs) have proven to be powerful predictors and are widely used for various tasks. Credible uncertainty estimation of their predictions, however, is crucial for their deployment in many risk-sensitive applications. In this paper we present a novel and simple attack, which unlike adversarial attacks, does not cause incorrect predictions but instead cripples the network's capacity for uncertainty estimation. The result is that after the attack, the DNN is more confident of its incorrect predictions than about its correct ones without having its accuracy reduced. We present two versions of the attack. The first scenario focuses on a black-box regime (where the attacker has no knowledge of the target network) and the second scenario attacks a white-box setting. The proposed attack is only required to be of minuscule magnitude for its perturbations to cause severe uncertainty estimation damage, with larger magnitudes resulting in completely unusable uncertainty estimations. We demonstrate successful attacks on three of the most popular uncertainty estimation methods: the vanilla softmax score, Deep Ensembles and MC-Dropout. Additionally, we show an attack on SelectiveNet, the selective classification architecture. We test the proposed attack on several contemporary architectures such as MobileNetV2 and EfficientNetB0, all trained to classify ImageNet.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8cbccb6c-76e7-469b-99b0-9e4ae01400b6Cited by top-tier papers5
- Overcoming Common Flaws in the Evaluation of Selective Classification SystemsJeremias Traub, Till J. Bungert, Carsten T. Lüth, Michael Baumgartner et al.NeurIPS 2024 · 44 citations
- Calibrating Multimodal LearningHuan Ma, Qingyang Zhang, Changqing Zhang, Bingzhe Wu et al.ICML 2023 · 42 citations
- SAVE: Software-Implemented Fault Tolerance for Model Inference against GPU Memory Bit FlipsWenxin Zheng, Bin Xu, Jinyu Gu, Haibo ChenUSENIX ATC 2025 · 8 citations
- Towards Certification of Uncertainty Calibration under Adversarial AttacksCornelius Emde, Francesco Pinto, Thomas Lukasiewicz, Philip Torr et al.ICLR 2025 · 1 citation
- The Confidence Trap: Calibration Attacks for Graph Neural NetworksCuong Dang, Jiahao Zhang, Hieu Ta Quang, Dung Le et al.KDD 2026
Builds on1
Related papers
- Masksembles for Uncertainty EstimationNikita Durasov, Timur M. Bagautdinov, Pierre Baqué, Pascal FuaCVPR 2021
- What Can we Learn From The Selective Prediction And Uncertainty Estimation Performance Of 523 Imagenet Classifiers?Ido Galil, Mohammed Dabbah, Ran El-YanivICLR 2023 · 2 citations
- EMPIR: Ensembles of Mixed Precision Deep Networks for Increased Robustness Against Adversarial AttacksSanchari Sen, Balaraman Ravindran, Anand RaghunathanICLR 2020 · 69 citations
- Uncertainty-Aware Deep Neural Representations for Visual Analysis of Vector Field DataAtul Kumar, Siddharth Garg, Soumya DuttaIEEE VIS 2024 · 5 citations
- On the Perils of Cascading Robust ClassifiersRavi Mangal, Zifan Wang, Chi Zhang, Klas Leino et al.ICLR 2023
