On the Role of Randomization in Adversarially Robust Classification
Lucas Gnecco Heredia, Muni Sreenivas Pydi, Laurent Meunier, Benjamin Négrevergne, Yann Chevaleyre
Abstract
Deep neural networks are known to be vulnerable to small adversarial perturbations in test data. To defend against adversarial attacks, probabilistic classifiers have been proposed as an alternative to deterministic ones. However, literature has conflicting findings on the effectiveness of probabilistic classifiers in comparison to deterministic ones. In this paper, we clarify the role of randomization in building adversarially robust classifiers. Given a base hypothesis set of deterministic classifiers, we show the conditions under which a randomized ensemble outperforms the hypothesis set in adversarial risk, extending previous results. Additionally, we show that for any probabilistic binary classifier (including randomized ensembles), there exists a deterministic classifier that outperforms it. Finally, we give an explicit description of the deterministic hypothesis set that contains such a deterministic classifier for many types of commonly used probabilistic classifiers, i.e. randomized ensembles and parametric/input noise injection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ae9ab9ea-adb1-4612-9087-e336ab26be74Cited by top-tier papers1
Ask how each one uses itBuilds on13
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- DVERGE: Diversifying Vulnerabilities for Enhanced Robust Generation of EnsemblesHuanrui Yang, Jingyang Zhang, Hongliang Dong, Nathan Inkawhich et al.NeurIPS 2020 · 144 citations
- TRS: Transferability Reduced Ensemble via Promoting Gradient Diversity and Model SmoothnessZhuolin Yang, Linyi Li, Xiaojun Xu, Shiliang Zuo et al.NeurIPS 2021 · 76 citations
- Randomization matters How to defend against strong adversarial attacksRafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre et al.ICML 2020 · 66 citations
Related papers
- Adversarial Vulnerability of Randomized EnsemblesHassan Dbouk, Naresh R. ShanbhagICML 2022 · 8 citations
- PopSkipJump: Decision-Based Attack for Probabilistic ClassifiersCarl-Johann Simon-Gabriel, Noman Ahmed Sheikh, Andreas KrauseICML 2021 · 4 citations
- On the Robustness of Randomized Ensembles to Adversarial PerturbationsHassan Dbouk, Naresh R. ShanbhagICML 2023 · 8 citations
- Adversarial Defense via Learning to Generate Diverse AttacksYunseok Jang, Tianchen Zhao, Seunghoon Hong, Honglak LeeICCV 2019 · 88 citations
- Self-ensemble Adversarial Training for Improved RobustnessHongjun Wang, Yisen WangICLR 2022 · 61 citations
