Understanding Intrinsic Robustness Using Label Uncertainty
Xiao Zhang, David E. Evans
摘要
A fundamental question in adversarial machine learning is whether a robust classifier exists for a given task. A line of research has made some progress towards this goal by studying the concentration of measure, but we argue standard concentration fails to fully characterize the intrinsic robustness of a classification problem since it ignores data labels which are essential to any classification task. Building on a novel definition of label uncertainty, we empirically demonstrate that error regions induced by state-of-the-art models tend to have much higher label uncertainty than randomly-selected subsets. This observation motivates us to adapt a concentration estimation algorithm to account for label uncertainty, resulting in more accurate intrinsic robustness measures for benchmark image classification problems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- MalCertain: Enhancing Deep Neural Network Based Android Malware Detection by Tackling Prediction UncertaintyHaodong Li, Guosheng Xu, Liu Wang, Xusheng Xiao 等ICSE 2024 · 被引用 17 次
- Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial RobustnessAmbar Pal, Jeremias Sulam, René VidalNeurIPS 2023 · 被引用 15 次
- How to Enable Effective Cooperation Between Humans and NLP Models: A Survey of Principles, Formalizations, and BeyondChen Huang, Yang Deng, Wenqiang Lei, Jiancheng Lv 等ACL 2025
它引用的顶会 Paper9
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha 等S&P 2016 · 被引用 3,275 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 被引用 1,026 次
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 被引用 917 次
- Towards Stable and Efficient Training of Verifiably Robust Neural NetworksHuan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal 等ICLR 2020 · 被引用 384 次
相关 Paper
- Improved Estimation of Concentration Under ℓp-Norm Distance Metrics Using Half SpacesJack Prescott, Xiao Zhang, David E. EvansICLR 2021 · 被引用 5 次
- Beyond Categorical Label Representations for Image ClassificationBoyuan Chen, Yu Li, Sunand Raghupathi, Hod LipsonICLR 2021
- On the Error Resistance of Hinge-Loss MinimizationKunal TalwarNeurIPS 2020 · 被引用 7 次
- Human Uncertainty Makes Classification More RobustJoshua C. Peterson, Ruairidh M. Battleday, Thomas L. Griffiths, Olga RussakovskyICCV 2019 · 被引用 362 次
- Combating Noise: Semi-supervised Learning by Region Uncertainty QuantificationZhenyu Wang, Ya-Li Li, Ye Guo, Shengjin WangNeurIPS 2021 · 被引用 34 次
