Incorporating Label Uncertainty in Understanding Adversarial Robustness

Incorporating Label Uncertainty in Understanding Adversarial Robustness
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
ArXiv
影响因子:
--
通讯作者:
Xiao Zhang;David Evans
Xiao Zhang;David Evans
中科院分区:
其他
文献类型:
--
作者:
Xiao Zhang;David Evans

文献摘要

相似文献

对抗性机器学习的一个基本问题是,对于给定的任务,是否存在鲁棒分类器。通过研究测量的浓度,但不考虑数据标签,一系列研究已经朝着这一目标取得了进展。我们认为,标准集中不能完全表征分类问题的内在鲁棒性,因为它忽略了对任何分类任务至关重要的数据标签。基于标签不确定性的新定义,我们通过经验证明,与随机选择的子集相比,由最先进模型引起的错误区域往往具有更高的标签不确定性。这一观察结果促使我们采用浓度估计算法来考虑标签的不确定性,从而为基准图像分类问题提供更准确的内在鲁棒性度量。我们进一步提供的经验证据表明,为基于标签不确定性的分类器添加弃权选项可以帮助提高模型的干净和鲁棒准确性。
A fundamental question in adversarial machine learning is whether a robust classi-fier exists for a given task. A line of research has made progress towards this goal by studying concentration of measure, but without considering data labels. We argue that the standard concentration fails to fully characterize the intrinsic robustness of a classification problem, since it ignores data labels which are essential to any classification task. Building on a novel definition of label uncertainty, we empirically demonstrate that error regions induced by state-of-the-art models tend to have much higher label uncertainty compared with randomly-selected subsets. This observation motivates us to adapt a concentration estimation algorithm to account for label uncertainty, resulting in more accurate intrinsic robustness measures for benchmark image classification problems. We further provide empirical evidence showing that adding an abstain option for classifiers based on label uncertainty can help improve both the clean and robust accuracies of models.