Interpreting Robust Optimization via Adversarial Influence Functions
Zhun Deng, Cynthia Dwork, Jialiang Wang, Linjun Zhang
摘要
Robust optimization has been widely used in nowadays data science, especially in adversarial training. However, little research has been done to quantify how robust optimization changes the optimizers and the prediction losses comparing to standard training. In this paper, inspired by the influence function in robust statistics, we introduce the Adversarial Influence Function (AIF) as a tool to investigate the solution produced by robust optimization. The proposed AIF enjoys a closed-form and can be calculated efficiently. To illustrate the usage of AIF, we apply it to study model sensitivity -- a quantity defined to capture the change of prediction losses on the natural data after implementing robust optimization. We use AIF to analyze how model complexity and randomized smoothing affect the model sensitivity with respect to specific models. We further derive AIF for kernel regressions, with a particular application to neural tangent kernels, and experimentally demonstrate the effectiveness of the proposed AIF. Lastly, the theories of AIF will be extended to distributional robust optimization.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- When and How Mixup Improves CalibrationLinjun Zhang, Zhun Deng, Kenji Kawaguchi, James ZouICML 2022 · 被引用 79 次
- Adversarial Training Helps Transfer Learning via Better RepresentationsZhun Deng, Linjun Zhang, Kailas Vodrahalli, Kenji Kawaguchi 等NeurIPS 2021 · 被引用 60 次
- MUter: Machine Unlearning on Adversarially Trained ModelsJunxu Liu, Mingsheng Xue, Jian Lou, Xiaoyu Zhang 等ICCV 2023 · 被引用 36 次
- FIFA: Making Fairness More Generalizable in Classifiers Trained on Imbalanced DataZhun Deng, Jiayao Zhang, Linjun Zhang, Ting Ye 等ICLR 2023 · 被引用 7 次
- Safety-Efficacy Trade Off: Robustness against Data-PoisoningDiego Granziol, Ulugbek AbdimanabovICML 2026 · 被引用 1 次
相关 Paper
- Rethinking Influence Functions of Neural Networks in the Over-Parameterized RegimeRui Zhang, Shihua ZhangAAAI 2022 · 被引用 32 次
- Characterizing the Influence of Graph ElementsZizhang Chen, Peizhao Li, Hongfu Liu, Pengyu HongICLR 2023 · 被引用 1 次
- DRF: Improving Certified Robustness via Distributional Robustness FrameworkZekai Wang, Zhengyu Zhou, Weiwei LiuAAAI 2024 · 被引用 7 次
- A Versatile Influence Function for Data Attribution with Non-Decomposable LossJunwei Deng, Weijing Tang, Jiaqi W. MaICML 2025
- Do Wider Neural Networks Really Help Adversarial Robustness?Boxi Wu, Jinghui Chen, Deng Cai, Xiaofei He 等NeurIPS 2021 · 被引用 107 次
