Understanding the Limitations of Conditional Generative Models
Ethan Fetaya, Jörn-Henrik Jacobsen, Will Grathwohl, Richard S. Zemel
摘要
Class-conditional generative models hold promise to overcome the shortcomings of their discriminative counterparts. They are a natural choice to solve discriminative tasks in a robust manner as they jointly optimize for predictive performance and accurate modeling of the input distribution. In this work, we investigate robust classification with likelihood-based generative models from a theoretical and practical perspective to investigate if they can deliver on their promises. Our analysis focuses on a spectrum of robustness properties: (1) Detection of worst-case outliers in the form of adversarial examples; (2) Detection of average-case outliers in the form of ambiguous inputs and (3) Detection of incorrectly labeled in-distribution inputs. Our theoretical result reveals that it is impossible to guarantee detectability of adversarially-perturbed inputs even for near-optimal generative classifiers. Experimentally, we find that while we are able to train robust models for MNIST, robustness completely breaks down on CIFAR10. We relate this failure to various undesirable model properties that can be traced to the maximum likelihood training objective. Despite being a common choice in the literature, our results indicate that likelihood-based conditional generative models may are surprisingly ineffective for robust classification.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper14
- Adversarial Example Does Good: Preventing Painting Imitation from Diffusion Models via Adversarial ExamplesChumeng Liang, Xiaoyu Wu, Yang Hua, Jiaru Zhang 等ICML 2023 · 被引用 200 次
- CARD: Classification and Regression Diffusion ModelsXizewen Han, Huangjie Zheng, Mingyuan ZhouNeurIPS 2022 · 被引用 185 次
- GMMSeg: Gaussian Mixture based Generative Semantic Segmentation ModelsChen Liang, Wenguan Wang, Jiaxu Miao, Yi YangNeurIPS 2022 · 被引用 185 次
- Invertible DenseNets with Concatenated LipSwishYura Perugachi-Diaz, Jakub M. Tomczak, Sandjai BhulaiNeurIPS 2021 · 被引用 29 次
- Evaluating State-of-the-Art Classification Models Against Bayes OptimalityRyan Theisen, Huan Wang, Lav R. Varshney, Caiming Xiong 等NeurIPS 2021 · 被引用 21 次
它引用的顶会 Paper1
相关 Paper
- Multi-Class Data Description for Out-of-distribution DetectionDongha Lee, Sehun Yu, Hwanjo YuKDD 2020 · 被引用 22 次
- Your classifier is secretly an energy based model and you should treat it like oneWill Grathwohl, Kuan-Chieh Wang, Jörn-Henrik Jacobsen, David Duvenaud 等ICLR 2020 · 被引用 643 次
- Training Normalizing Flows with the Information Bottleneck for Competitive Generative ClassificationLynton Ardizzone, Radek Mackowiak, Carsten Rother, Ullrich KötheNeurIPS 2020 · 被引用 62 次
- Your Out-of-Distribution Detection Method is Not Robust!Mohammad Azizmalayeri, Arshia Soltani Moakhar, Arman Zarei, Reihaneh Zohrabi 等NeurIPS 2022 · 被引用 29 次
- Robust Classification via a Single Diffusion ModelHuanran Chen, Yinpeng Dong, Zhengyi Wang, Xiao Yang 等ICML 2024 · 被引用 94 次
