Lune

ICLR2023Top-tier venue

Fundamental limits on the robustness of image classifiers

Zheng Dai, David Gifford

2023Year

Abstract

We prove that image classifiers are fundamentally sensitive to small perturbations in their inputs. Specifically, we show that given some image space of nn-by-nn images, all but a tiny fraction of images in any image class induced over that space can be moved outside that class by adding some perturbation whose pp-norm is O(n1/max⁡(p,1))O(n^{1/\max{(p,1)}}), as long as that image class takes up at most half of the image space. We then show that O(n1/max⁡(p,1))O(n^{1/\max{(p,1)}}) is asymptotically optimal. Finally, we show that an increase in the bit depth of the image space leads to a loss in robustness. We supplement our results with a discussion of their implications for vision systems.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines