Understanding the Limitations of Conditional Generative Models
Ethan Fetaya, Jörn-Henrik Jacobsen, Will Grathwohl, Richard S. Zemel
Abstract
Class-conditional generative models hold promise to overcome the shortcomings of their discriminative counterparts. They are a natural choice to solve discriminative tasks in a robust manner as they jointly optimize for predictive performance and accurate modeling of the input distribution. In this work, we investigate robust classification with likelihood-based generative models from a theoretical and practical perspective to investigate if they can deliver on their promises. Our analysis focuses on a spectrum of robustness properties: (1) Detection of worst-case outliers in the form of adversarial examples; (2) Detection of average-case outliers in the form of ambiguous inputs and (3) Detection of incorrectly labeled in-distribution inputs. Our theoretical result reveals that it is impossible to guarantee detectability of adversarially-perturbed inputs even for near-optimal generative classifiers. Experimentally, we find that while we are able to train robust models for MNIST, robustness completely breaks down on CIFAR10. We relate this failure to various undesirable model properties that can be traced to the maximum likelihood training objective. Despite being a common choice in the literature, our results indicate that likelihood-based conditional generative models may are surprisingly ineffective for robust classification.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 96aae410-dbdb-4797-942b-1d0252a2e7f2Cited by top-tier papers14
- Adversarial Example Does Good: Preventing Painting Imitation from Diffusion Models via Adversarial ExamplesChumeng Liang, Xiaoyu Wu, Yang Hua, Jiaru Zhang et al.ICML 2023 · 200 citations
- CARD: Classification and Regression Diffusion ModelsXizewen Han, Huangjie Zheng, Mingyuan ZhouNeurIPS 2022 · 185 citations
- GMMSeg: Gaussian Mixture based Generative Semantic Segmentation ModelsChen Liang, Wenguan Wang, Jiaxu Miao, Yi YangNeurIPS 2022 · 185 citations
- Invertible DenseNets with Concatenated LipSwishYura Perugachi-Diaz, Jakub M. Tomczak, Sandjai BhulaiNeurIPS 2021 · 29 citations
- Evaluating State-of-the-Art Classification Models Against Bayes OptimalityRyan Theisen, Huan Wang, Lav R. Varshney, Caiming Xiong et al.NeurIPS 2021 · 21 citations
Builds on1
Related papers
- Multi-Class Data Description for Out-of-distribution DetectionDongha Lee, Sehun Yu, Hwanjo YuKDD 2020 · 22 citations
- Your classifier is secretly an energy based model and you should treat it like oneWill Grathwohl, Kuan-Chieh Wang, Jörn-Henrik Jacobsen, David Duvenaud et al.ICLR 2020 · 643 citations
- Training Normalizing Flows with the Information Bottleneck for Competitive Generative ClassificationLynton Ardizzone, Radek Mackowiak, Carsten Rother, Ullrich KötheNeurIPS 2020 · 62 citations
- Your Out-of-Distribution Detection Method is Not Robust!Mohammad Azizmalayeri, Arshia Soltani Moakhar, Arman Zarei, Reihaneh Zohrabi et al.NeurIPS 2022 · 29 citations
- Robust Classification via a Single Diffusion ModelHuanran Chen, Yinpeng Dong, Zhengyi Wang, Xiao Yang et al.ICML 2024 · 94 citations
