Defense Through Diverse Directions
Christopher M. Bender, Yang Li, Yifeng Shi, Michael K. Reiter, Junier Oliva
摘要
In this work we develop a novel Bayesian neural network methodology to achieve strong adversarial robustness without the need for online adversarial training. Unlike previous efforts in this direction, we do not rely solely on the stochasticity of network weights by minimizing the divergence between the learned parameter distribution and a prior. Instead, we additionally require that the model maintain some expected uncertainty with respect to all input covariates. We demonstrate that by encouraging the network to distribute evenly across inputs, the network becomes less susceptible to localized, brittle features which imparts a natural robustness to targeted perturbations. We show empirical robustness on several benchmark datasets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Demystifying the Adversarial Robustness of Random Transformation DefensesChawin Sitawarin, Zachary J. Golan-Strieb, David A. WagnerICML 2022 · 被引用 26 次
- How Sampling Impacts the Robustness of Stochastic Neural NetworksSina Däubener, Asja FischerNeurIPS 2022 · 被引用 1 次
它引用的顶会 Paper1
相关 Paper
- Encoding Robustness to Image Style via Adversarial Feature PerturbationsManli Shu, Zuxuan Wu, Micah Goldblum, Tom GoldsteinNeurIPS 2021 · 被引用 23 次
- Robust Bayesian Neural Networks by Spectral Expectation Bound RegularizationJiaru Zhang, Yang Hua, Zhengui Xue, Tao Song 等CVPR 2021
- Robustness to corruption in pre-trained Bayesian neural networksXi Wang, Laurence AitchisonICLR 2023
- Quantifying Uncertainty in the Presence of Distribution ShiftsYuli Slavutsky, David M. BleiNeurIPS 2025 · 被引用 2 次
- Dangers of Bayesian Model Averaging under Covariate ShiftPavel Izmailov, Patrick Nicholson, Sanae Lotfi, Andrew Gordon WilsonNeurIPS 2021 · 被引用 51 次
