Neural Architecture Design and Robustness: A Dataset
Steffen Jung, Jovita Lukasik, Margret Keuper
Abstract
Deep learning models have proven to be successful in a wide range of machine learning tasks. Yet, they are often highly sensitive to perturbations on the input data which can lead to incorrect decisions with high confidence, hampering their deployment for practical use-cases. Thus, finding architectures that are (more) robust against perturbations has received much attention in recent years. Just like the search for well-performing architectures in terms of clean accuracy, this usually involves a tedious trial-and-error process with one additional challenge: the evaluation of a network's robustness is significantly more expensive than its evaluation for clean accuracy. Thus, the aim of this paper is to facilitate better streamlined research on architectural design choices with respect to their impact on robustness as well as, for example, the evaluation of surrogate measures for robustness. We therefore borrow one of the most commonly considered search spaces for neural architecture search for image classification, NAS-Bench-201, which contains a manageable size of 6 466 non-isomorphic network designs. We evaluate all these networks on a range of common adversarial attacks and corruption types and introduce a database on neural architecture design and robustness evaluations. We further present three exemplary use cases of this dataset, in which we (i) benchmark robustness measurements based on Jacobian and Hessian matrices for their robustness predictability, (ii) perform neural architecture search on robust accuracies, and (iii) provide an initial analysis of how architectural design choices affect robustness. We find that carefully crafting the topology of a network can have substantial impact on its robustness, where networks with the same parameter count range in mean adversarial robust accuracy from 20% -41%. Code and data is available at http://robustness.vision/ .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers9
- CosPGD: an efficient white-box adversarial attack for pixel-wise prediction tasksShashank Agnihotri, Steffen Jung, Margret KeuperICML 2024 · 35 citations
- DiffusionNAG: Predictor-guided Neural Architecture Generation with Diffusion ModelsSohyun An, Hayeon Lee, Jaehyeong Jo, Seanie Lee et al.ICLR 2024 · 21 citations
- Surprisingly Strong Performance Prediction with Neural Graph FeaturesGabriela Kadlecová, Jovita Lukasik, Martin Pilát, Petra Vidnerová et al.ICML 2024 · 12 citations
- Generalizable Lightweight Proxy for Robust NAS against Diverse PerturbationsHyeonjeong Ha, Minseon Kim, Sung Ju HwangNeurIPS 2023 · 12 citations
- A Benchmark Study on CalibrationLinwei Tao, Younan Zhu, Haolan Guo, Minjing Dong et al.ICLR 2024 · 10 citations
Builds on14
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- NAS-Bench-201: Extending the Scope of Reproducible Neural Architecture SearchXuanyi Dong, Yi YangICLR 2020 · 825 citations
- PC-DARTS: Partial Channel Connections for Memory-Efficient Architecture SearchYuhui Xu, Lingxi Xie, Xiaopeng Zhang, Xin Chen et al.ICLR 2020 · 691 citations
- Understanding and Robustifying Differentiable Architecture SearchArber Zela, Thomas Elsken, Tonmoy Saikia, Yassine Marrakchi et al.ICLR 2020 · 408 citations
- BANANAS: Bayesian Optimization with Neural Architectures for Neural Architecture SearchColin White, Willie Neiswanger, Yash SavaniAAAI 2021 · 401 citations
Related papers
- Robust NAS under adversarial training: benchmark, theory, and beyondYongtao Wu, Fanghui Liu, Carl-Johann Simon-Gabriel, Grigorios Chrysos et al.ICLR 2024 · 10 citations
- Towards Accurate and Robust Architectures via Neural Architecture SearchYuwei Ou, Yuqi Feng, Yanan SunCVPR 2024 · 8 citations
- When NAS Meets Robustness: In Search of Robust Architectures Against Adversarial AttacksMinghao Guo, Yuzhe Yang, Rui Xu, Ziwei Liu et al.CVPR 2020
- NASGuard: A Novel Accelerator Architecture for Robust Neural Architecture Search (NAS) NetworksXingbin Wang, Boyan Zhao, Rui Hou, Amro Awad et al.ISCA 2021 · 9 citations
- DSRNA: Differentiable Search of Robust Neural ArchitecturesRamtin Hosseini, Xingyi Yang, Pengtao XieCVPR 2021
