Fundamental limits on the robustness of image classifiers
Zheng Dai, David Gifford
2023年份
摘要
We prove that image classifiers are fundamentally sensitive to small perturbations in their inputs. Specifically, we show that given some image space of -by- images, all but a tiny fraction of images in any image class induced over that space can be moved outside that class by adding some perturbation whose -norm is , as long as that image class takes up at most half of the image space. We then show that is asymptotically optimal. Finally, we show that an increase in the bit depth of the image space leads to a loss in robustness. We supplement our results with a discussion of their implications for vision systems.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Feature compression is the root cause of adversarial fragility in neural networksJingchao Gao, Ziqing Lu, Raghu Mudumbai, Xiaodong Wu 等ICLR 2026 · 被引用 3 次
- Why adversarial training can hurt robust accuracyJacob Clarysse, Julia Hörrmann, Fanny YangICLR 2023 · 被引用 6 次
- Adaptive Image Anonymization in the Context of Image Classification with Neural NetworksNadiya Shvai, Arcadi Llanza Carmona, Amir NakibICCV 2023 · 被引用 6 次
- Defending Against Universal Perturbations With Shared Adversarial TrainingChaithanya Kumar Mummadi, Thomas Brox, Jan Hendrik MetzenICCV 2019 · 被引用 61 次
- Adversarial Robustness Limits via Scaling-Law and Human-Alignment StudiesBrian R. Bartoldson, James Diffenderfer, Konstantinos Parasyris, Bhavya KailkhuraICML 2024 · 被引用 45 次
