Provably Adversarially Robust Detection of Out-of-Distribution Data (Almost) for Free
Alexander Meinke, Julian Bitterwolf, Matthias Hein
摘要
The application of machine learning in safety-critical systems requires a reliable assessment of uncertainty. However, deep neural networks are known to produce highly overconfident predictions on out-of-distribution (OOD) data. Even if trained to be non-confident on OOD data, one can still adversarially manipulate OOD data so that the classifier again assigns high confidence to the manipulated samples. We show that two previously published defenses can be broken by better adapted attacks, highlighting the importance of robustness guarantees around OOD data. Since the existing method for this task is hard to train and significantly limits accuracy, we construct a classifier that can simultaneously achieve provably adversarially robust OOD detection and high clean accuracy. Moreover, by slightly modifying the classifier's architecture our method provably avoids the asymptotic overconfidence problem of standard neural networks. We provide code for all our experiments. †
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- In or Out? Fixing ImageNet Out-of-Distribution Detection EvaluationJulian Bitterwolf, Maximilian Müller, Matthias HeinICML 2023 · 被引用 154 次
- RODEO: Robust Outlier Detection via Exposing Adaptive Out-of-Distribution SamplesHossein Mirzaei, Mohammad Jafari, Hamid Reza Dehbashi, Ali Ansari 等ICML 2024 · 被引用 13 次
- Open Set Label Shift with Test Time Out-of-Distribution ReferenceChangkun Ye, Russell Tsuchida, Lars Petersson, Nick BarnesCVPR 2025
- Adversarially Robust Out-of-Distribution Detection Using Lyapunov-Stabilized EmbeddingsHossein Mirzaei, Mackenzie W. MathisICLR 2025
- Inside-Out: Measuring Generalization in Vision Transformers Through Inner WorkingsYunxiang Peng, Mengmeng Ma, Ziyu Yao, Xi PengCVPR 2026
它引用的顶会 Paper11
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Energy-based Out-of-distribution DetectionWeitang Liu, Xiaoyun Wang, John D. Owens, Yixuan LiNeurIPS 2020 · 被引用 2,213 次
- Improving Robustness using Generated DataSven Gowal, Sylvestre-Alvise Rebuffi, Olivia Wiles, Florian Stimberg 等NeurIPS 2021 · 被引用 384 次
- Towards Stable and Efficient Training of Verifiably Robust Neural NetworksHuan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal 等ICLR 2020 · 被引用 384 次
- Being Bayesian, Even Just a Bit, Fixes Overconfidence in ReLU NetworksAgustinus Kristiadi, Matthias Hein, Philipp HennigICML 2020 · 被引用 344 次
相关 Paper
- Towards neural networks that provably know when they don't knowAlexander Meinke, Matthias HeinICLR 2020 · 被引用 151 次
- Certifiably Adversarially Robust Detection of Out-of-Distribution DataJulian Bitterwolf, Alexander Meinke, Matthias HeinNeurIPS 2020 · 被引用 91 次
- iDECODe: In-Distribution Equivariance for Conformal Out-of-Distribution DetectionRamneet Kaur, Susmit Jha, Anirban Roy, Sangdon Park 等AAAI 2022 · 被引用 53 次
- Self-Supervised Learning for Generalizable Out-of-Distribution DetectionSina Mohseni, Mandar Pitale, J. B. S. Yadawa, Zhangyang WangAAAI 2020 · 被引用 229 次
- Enhancing Adversarial Robustness with Conformal Prediction: A Framework for Guaranteed Model ReliabilityJie Bao, Chuangyin Dang, Rui Luo, Hanwei Zhang 等ICML 2025
