Adversarial Robustness of Supervised Sparse Coding
Jeremias Sulam, Ramchandran Muthukumar, Raman Arora
摘要
Several recent results provide theoretical insights into the phenomena of adversarial examples. Existing results, however, are often limited due to a gap between the simplicity of the models studied and the complexity of those deployed in practice. In this work, we strike a better balance by considering a model that involves learning a representation while at the same time giving a precise generalization bound and a robustness certificate. We focus on the hypothesis class obtained by combining a sparsity-promoting encoder coupled with a linear classifier, and show an interesting interplay between the expressivity and stability of the (supervised) representation map and a notion of margin in the feature space. We bound the robust risk (to -bounded perturbations) of hypotheses parameterized by dictionaries that achieve a mild encoder gap on training data. Furthermore, we provide a robustness certificate for end-to-end classification. We demonstrate the applicability of our analysis by computing certified accuracy on real data, and compare with other alternatives for certified robustness.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- A Geometric Analysis of Neural Collapse with Unconstrained FeaturesZhihui Zhu, Tianyu Ding, Jinxin Zhou, Xiao Li 等NeurIPS 2021 · 被引用 303 次
- Predify: Augmenting deep neural networks with brain-inspired predictive coding dynamicsBhavin Choksi, Milad Mozafari, Callum Biggs O'May, Benjamin Ador 等NeurIPS 2021 · 被引用 48 次
- Learning sparse features can lead to overfitting in neural networksLeonardo Petrini, Francesco Cagnetta, Eric Vanden-Eijnden, Matthieu WyartNeurIPS 2022 · 被引用 47 次
- Revisiting Sparse Convolutional Model for Visual RecognitionXili Dai, Mingyang Li, Pengyuan Zhai, Shengbang Tong 等NeurIPS 2022 · 被引用 45 次
- What's in a Prior? Learned Proximal Networks for Inverse ProblemsZhenghan Fang, Sam Buchanan, Jeremias SulamICLR 2024 · 被引用 27 次
它引用的顶会 Paper3
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 被引用 1,026 次
- Feature Purification: How Adversarial Training Performs Robust Deep LearningZeyuan Allen-Zhu, Yuanzhi LiFOCS 2021 · 被引用 83 次
- Dataless Model Selection With the Deep Frame PotentialCalvin Murdock, Simon LuceyCVPR 2020
相关 Paper
- Relaxing Local RobustnessKlas Leino, Matt FredriksonNeurIPS 2021 · 被引用 12 次
- Adversarial robustness via robust low rank representationsPranjal Awasthi, Himanshu Jain, Ankit Singh Rawat, Aravindan VijayaraghavanNeurIPS 2020 · 被引用 26 次
- Confidence-Aware Training of Smoothed Classifiers for Certified RobustnessJongheon Jeong, Seojin Kim, Jinwoo ShinAAAI 2023 · 被引用 14 次
- Certified Robust Accuracy of Neural Networks Are Bounded Due to Bayes ErrorsRuihan Zhang, Jun SunCAV 2024 · 被引用 5 次
- Fast Adversarial Robustness Certification of Nearest Prototype Classifiers for Arbitrary SeminormsSascha Saralajew, Lars Holdijk, Thomas VillmannNeurIPS 2020 · 被引用 27 次
