Can we have it all? On the Trade-off between Spatial and Adversarial Robustness of Neural Networks
Sandesh Kamath, Amit Deshpande, Subrahmanyam Kambhampati Venkata, Vineeth N. Balasubramanian
摘要
Non-)robustness of neural networks to small, adversarial pixel-wise perturbations, and as more recently shown, to even random spatial transformations (e.g., translations, rotations) entreats both theoretical and empirical understanding. Spatial robustness to random translations and rotations is commonly attained via equivariant models (e.g., StdCNNs, GCNNs) and training augmentation, whereas adversarial robustness is typically achieved by adversarial training. In this paper, we prove a quantitative trade-off between spatial and adversarial robustness in a simple statistical setting. We complement this empirically by showing that: (a) as the spatial robustness of equivariant models improves by training augmentation with progressively larger transformations, their adversarial robustness worsens progressively, and (b) as the state-of-the-art robust models are adversarially trained with progressively larger pixel-wise perturbations, their spatial robustness drops progressively. Towards achieving Pareto-optimality in this trade-off, we propose a method based on curriculum learning that trains gradually on more difficult perturbations (both spatial and adversarial) to improve spatial and adversarial robustness simultaneously. Spatial-Adversarial Robustness Trade-off In this section, we prove the trade-off between spatial and adversarial robustness theoretically, and support this result with experiments in Sec 4. We use A(x) to denote an adversarial ∞ perturbation and r(x) to denote a random spatial transformation. Equivariant model constructions often consider a group of transformations and construct a neural network model invariant to this group. For simplicity, we consider a cyclic group that can model a rotation group (e.g., integer multiples of 30 • ), or horizontal/vertical translations (e.g., horizontal translations by multiples of, say, ±4 pixels).
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- On the Limitations of Stochastic Pre-processing DefensesYue Gao, Ilia Shumailov, Kassem Fawaz, Nicolas PapernotNeurIPS 2022 · 被引用 35 次
- Robust Perception through EquivarianceChengzhi Mao, Lingyu Zhang, Abhishek Vaibhav Joshi, Junfeng Yang 等ICML 2023 · 被引用 10 次
- Invariance-Aware Randomized Smoothing CertificatesJan Schuchardt, Stephan GünnemannNeurIPS 2022 · 被引用 8 次
- (Provable) Adversarial Robustness for Group Equivariant Tasks: Graphs, Point Clouds, Molecules, and MoreJan Schuchardt, Yan Scholten, Stephan GünnemannNeurIPS 2023 · 被引用 5 次
- Does Progress On Object Recognition Benchmarks Improve Generalization on Crowdsourced, Global Data?Megan Richards, Polina Kirichenko, Diane Bouchacourt, Mark IbrahimICLR 2024 · 被引用 2 次
它引用的顶会 Paper9
- The Many Faces of Robustness: A Critical Analysis of Out-of-Distribution GeneralizationDan Hendrycks, Steven Basart, Norman Mu, Saurav Kadavath 等ICCV 2021 · 被引用 2,294 次
- Measuring Robustness to Natural Distribution Shifts in Image ClassificationRohan Taori, Achal Dave, Vaishaal Shankar, Nicholas Carlini 等NeurIPS 2020 · 被引用 731 次
- A Closer Look at Accuracy vs. RobustnessYao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov 等NeurIPS 2020 · 被引用 336 次
- Scale-Equivariant Steerable NetworksIvan Sosnovik, Michal Szmaja, Arnold W. M. SmeuldersICLR 2020 · 被引用 169 次
- Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial PerturbationsFlorian Tramèr, Jens Behrmann, Nicholas Carlini, Nicolas Papernot 等ICML 2020 · 被引用 103 次
相关 Paper
- Bridging Symmetry and Robustness: On the Role of Equivariance in Enhancing Adversarial RobustnessLongwei Wang, Ifrat Ikhtear Uddin, KC Santosh, Chaowei Zhang 等NeurIPS 2025 · 被引用 12 次
- Data Augmentation Can Improve RobustnessSylvestre-Alvise Rebuffi, Sven Gowal, Dan Andrei Calian, Florian Stimberg 等NeurIPS 2021 · 被引用 427 次
- On the Tradeoff Between Robustness and FairnessXinsong Ma, Zekai Wang, Weiwei LiuNeurIPS 2022 · 被引用 64 次
- Attribute-Guided Adversarial Training for Robustness to Natural PerturbationsTejas Gokhale, Rushil Anirudh, Bhavya Kailkhura, Jayaraman J. Thiagarajan 等AAAI 2021 · 被引用 42 次
- Encoding Robustness to Image Style via Adversarial Feature PerturbationsManli Shu, Zuxuan Wu, Micah Goldblum, Tom GoldsteinNeurIPS 2021 · 被引用 23 次
