Stratified Adversarial Robustness with Rejection

Stratified Adversarial Robustness with Rejection
复制标题

DOI:
10.48550/arxiv.2305.01139
复制
发表时间:
2023-05
期刊:
ArXiv
影响因子:
--
通讯作者:
Jiefeng Chen;Jayaram Raghuram;Jihye Choi;Xi Wu;Yingyu Liang;S. Jha
Jiefeng Chen;Jayaram Raghuram;Jihye Choi;Xi Wu;Yingyu Liang;S. Jha
中科院分区:
其他
文献类型:
--
作者:
Jiefeng Chen;Jayaram Raghuram;Jihye Choi;Xi Wu;Yingyu Liang;S. Jha

文献摘要

相似文献

最近,人们对通过带有拒绝选项(也称为选择性分类器)的对抗训练来提高对抗鲁棒性产生了新的兴趣。虽然在许多应用中拒绝可能会产生成本,但现有研究通常将拒绝受扰动的输入视为零成本,这可能导致大量可以正确分类的轻微受扰动的输入被拒绝。在这项工作中,我们在分层拒绝设置下研究带有拒绝的对抗鲁棒分类,其中拒绝成本由在扰动幅度上单调非递增的拒绝损失函数来建模。我们从理论上分析了分层拒绝设置,并提出了一种新的防御方法——基于一致预测的拒绝的对抗训练(CPR)——用于构建一个鲁棒的选择性分类器。在图像数据集上的实验表明,所提出的方法在强自适应攻击下显著优于现有方法。例如,在CIFAR - 10上,CPR在已知和未知攻击下都将总鲁棒损失(针对不同的拒绝损失)至少降低了7.3%。
Recently, there is an emerging interest in adversarially training a classifier with a rejection option (also known as a selective classifier) for boosting adversarial robustness. While rejection can incur a cost in many applications, existing studies typically associate zero cost with rejecting perturbed inputs, which can result in the rejection of numerous slightly-perturbed inputs that could be correctly classified. In this work, we study adversarially-robust classification with rejection in the stratified rejection setting, where the rejection cost is modeled by rejection loss functions monotonically non-increasing in the perturbation magnitude. We theoretically analyze the stratified rejection setting and propose a novel defense method -- Adversarial Training with Consistent Prediction-based Rejection (CPR) -- for building a robust selective classifier. Experiments on image datasets demonstrate that the proposed method significantly outperforms existing methods under strong adaptive attacks. For instance, on CIFAR-10, CPR reduces the total robust loss (for different rejection losses) by at least 7.3% under both seen and unseen attacks.