Identifying Model Weakness with Adversarial Examiner
Michelle Shu, Chenxi Liu, Weichao Qiu, Alan L. Yuille
Abstract
Machine learning models are usually evaluated according to the average case performance on the test set. However, this is not always ideal, because in some sensitive domains (e.g. autonomous driving), it is the worst case performance that matters more. In this paper, we are interested in systematic exploration of the input data space to identify the weakness of the model to be evaluated. We propose to use an adversarial examiner in the testing stage. Different from the existing strategy to always give the same (distribution of) test data, the adversarial examiner will dynamically select the next test data to hand out based on the testing history so far, with the goal being to undermine the model's performance. This sequence of test data not only helps us understand the current model, but also serves as constructive feedback to help improve the model in the next iteration. We conduct experiments on ShapeNet object classification. We show that our adversarial examiner can successfully put more emphasis on the weakness of the model, preventing performance estimates from being overly optimistic.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers9
- SneakyPrompt: Jailbreaking Text-to-image Generative ModelsYuchen Yang, Bo Hui, Haolin Yuan, Neil Gong et al.S&P 2024 · 188 citations
- 3DB: A Framework for Debugging Computer Vision ModelsGuillaume Leclerc, Hadi Salman, Andrew Ilyas, Sai Vemprala et al.NeurIPS 2022 · 45 citations
- 3D-Aware Neural Body Fitting for Occlusion Robust 3D Human Pose EstimationYi Zhang, Pengliang Ji, Angtian Wang, Jieru Mei et al.ICCV 2023 · 44 citations
- Simulated Adversarial Testing of Face Recognition ModelsNataniel Ruiz, Adam Kortylewski, Weichao Qiu, Cihang Xie et al.CVPR 2022 · 8 citations
- A Black-Box Evaluation Framework for Semantic Robustness in Bird's Eye View DetectionFu Wang, Yanghao Zhang, Xiangyu Yin, Guangliang Cheng et al.AAAI 2025 · 1 citation
Builds on1
Related papers
- The Space of Adversarial StrategiesRyan Sheatsley, Blaine Hoak, Eric Pauley, Patrick D. McDanielUSENIX Security 2023
- Defending Against Universal Perturbations With Shared Adversarial TrainingChaithanya Kumar Mummadi, Thomas Brox, Jan Hendrik MetzenICCV 2019 · 61 citations
- Evaluating the Adversarial Robustness of Adaptive Test-time DefensesFrancesco Croce, Sven Gowal, Thomas Brunner, Evan Shelhamer et al.ICML 2022 · 85 citations
- Indicators of Attack Failure: Debugging and Improving Optimization of Adversarial ExamplesMaura Pintor, Luca Demetrio, Angelo Sotgiu, Ambra Demontis et al.NeurIPS 2022 · 39 citations
- Seeing is Not Believing: Adversarial Natural Object Optimization for Hard-Label 3D Scene AttacksDaizong Liu, Wei HuCVPR 2025
