Feature compression is the root cause of adversarial fragility in neural networks
Jingchao Gao, Ziqing Lu, Raghu Mudumbai, Xiaodong Wu, Jirong Yi, Myung Cho, Catherine Xu, Hui Xie, Weiyu Xu
摘要
In this paper, we uniquely study the adversarial robustness of deep neural networks (NN) for classification tasks against that of optimal classifiers. We look at the smallest magnitude of possible additive perturbations that can change a classifier's output. We provide a matrix-theoretic explanation of the adversarial fragility of deep neural networks for classification. In particular, our theoretical results show that a neural network's adversarial robustness can degrade as the input dimension increases. Analytically, we show that neural networks' adversarial robustness can be only of the best possible adversarial robustness of optimal classifiers. Our theories match remarkably well with numerical experiments of practically trained NN, including NN for ImageNet images. The matrix-theoretic explanation is consistent with an earlier information-theoretic feature-compression-based explanation for the adversarial fragility of neural networks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper11
- Feature Purification: How Adversarial Training Performs Robust Deep LearningZeyuan Allen-Zhu, Yuanzhi LiFOCS 2021 · 被引用 83 次
- Low Curvature Activations Reduce Overfitting in Adversarial TrainingVasu Singla, Sahil Singla, Soheil Feizi, David JacobsICCV 2021 · 被引用 49 次
- Evading Adversarial Example Detection Defenses with Orthogonal Projected Gradient DescentOliver Bryniarski, Nabeel Hingun, Pedro Pachuca, Vincent Wang 等ICLR 2022 · 被引用 43 次
- CGBA: Curvature-aware Geometric Black-box AttackMd Farhamdur Reza, Ali Rahmati, Tianfu Wu, Huaiyu DaiICCV 2023 · 被引用 33 次
- Adversarial Examples in Multi-Layer Random ReLU NetworksPeter L. Bartlett, Sébastien Bubeck, Yeshwanth CherapanamjeriNeurIPS 2021 · 被引用 33 次
相关 Paper
- Adversarial Robustness Guarantees for Random Deep Neural NetworksGiacomo De Palma, Bobak Toussi Kiani, Seth LloydICML 2021 · 被引用 10 次
- Exploring Architectural Ingredients of Adversarially Robust Deep Neural NetworksHanxun Huang, Yisen Wang, Sarah M. Erfani, Quanquan Gu 等NeurIPS 2021 · 被引用 124 次
- Fundamental limits on the robustness of image classifiersZheng Dai, David GiffordICLR 2023
- Towards Robustness of Deep Neural Networks via RegularizationYao Li, Martin Renqiang Min, Thomas C. M. Lee, Wenchao Yu 等ICCV 2021 · 被引用 8 次
- ε-weakened robustness of deep neural networksPei Huang, Yuting Yang, Minghao Liu, Fuqi Jia 等ISSTA 2022 · 被引用 10 次
