Hidden Cost of Randomized Smoothing

Hidden Cost of Randomized Smoothing
复制标题

DOI:
--
复制
发表时间:
2021
影响因子:
1.3
通讯作者:
Jeet Mohapatra;Ching-Yun Ko;Lily Weng;Pin-Yu Chen;Sijia Liu;L. Daniel
Jeet Mohapatra;Ching-Yun Ko;Lily Weng;Pin-Yu Chen;Sijia Liu;L. Daniel
中科院分区:
工程技术4区
文献类型:
--
作者:
Jeet Mohapatra;Ching-Yun Ko;Lily Weng;Pin-Yu Chen;Sijia Liu;L. Daniel

文献摘要

相似文献

现代机器学习模型的脆弱性引起了学术界和公众的广泛关注。虽然人们对设计对抗性攻击作为衡量神经网络鲁棒性的方法或设计带保证的最坏情况分析鲁棒性验证产生了巨大的兴趣,但很少有方法可以同时享受可扩展性和鲁棒性保证。作为这些尝试的替代方案,随机平滑采用不同的预测规则,可以实现统计鲁棒性参数,从而轻松扩展到大型网络。然而,在本文中,我们指出了当前随机平滑工作流程的副作用。具体来说,我们阐明并证明了两个要点:1)平滑分类器的决策边界将会缩小,导致分类准确率的差异; 2)在训练过程中应用噪声增强并不一定能解决由于学习目标不一致而导致的收缩问题。
The fragility of modern machine learning models has drawn a considerable amount of attention from both academia and the public. While immense interests were in either crafting adversarial attacks as a way to measure the robustness of neural networks or devising worst-case analytical robustness verification with guarantees, few methods could enjoy both scalability and robustness guarantees at the same time. As an alternative to these attempts, randomized smoothing adopts a different prediction rule that enables statistical robustness arguments which easily scale to large networks. However, in this paper, we point out the side effects of current randomized smoothing workflows. Specifically, we articulate and prove two major points: 1) the decision boundaries of smoothed clas-sifiers will shrink, resulting in disparity in class-wise accuracy; 2) applying noise augmentation in the training process does not necessarily resolve the shrinking issue due to the inconsistent learning objectives.