Empirically Measuring Concentration: Fundamental Limits on Intrinsic Robustness

Empirically Measuring Concentration: Fundamental Limits on Intrinsic Robustness
复制标题

DOI:
--
复制
发表时间:
2019-05
期刊:
--
影响因子:
--
通讯作者:
Saeed Mahloujifar;Xiao Zhang;Mohammad Mahmoody;David Evans
Saeed Mahloujifar;Xiao Zhang;Mohammad Mahmoody;David Evans
中科院分区:
其他
文献类型:
--
作者:
Saeed Mahloujifar;Xiao Zhang;Mohammad Mahmoody;David Evans

文献摘要

相似文献

最近的许多工作表明,可以通过最小程度地干扰正常输入来找到欺骗分类器的对抗性示例。从Gilmer等人(2018b)开始,最近的理论结果表明,如果输入来自集中的度量概率空间,那么具有小扰动的对抗示例是不可避免的。一个集中的空间具有这样的性质:根据强加的分布,任何具有$\Omega(1)$(例如,1/100)测度的子集与空间中几乎所有点(例如,99/100)的距离都很小。然而,尚不清楚这些理论结果是否适用于实际分布,如图像。本文提出了一种经验测量和限定具体数据集浓度的方法,该方法被证明收敛于实际浓度。我们用它来经验估计若干图像分类基准对$\ell_\infty$和$\ell_2$扰动的固有鲁棒性。我们的实验代码可以在这个https URL上找到。
Many recent works have shown that adversarial examples that fool classifiers can be found by minimally perturbing a normal input. Recent theoretical results, starting with Gilmer et al. (2018b), show that if the inputs are drawn from a concentrated metric probability space, then adversarial examples with small perturbation are inevitable. A concentrated space has the property that any subset with $\Omega(1)$ (e.g., 1/100) measure, according to the imposed distribution, has small distance to almost all (e.g., 99/100) of the points in the space. It is not clear, however, whether these theoretical results apply to actual distributions such as images. This paper presents a method for empirically measuring and bounding the concentration of a concrete dataset which is proven to converge to the actual concentration. We use it to empirically estimate the intrinsic robustness to $\ell_\infty$ and $\ell_2$ perturbations of several image classification benchmarks. Code for our experiments is available at this https URL.