Fairness Increases Adversarial Vulnerability

Fairness Increases Adversarial Vulnerability
复制标题

DOI:
10.48550/arxiv.2211.11835
复制
发表时间:
2022-11
期刊:
ArXiv
影响因子:
--
通讯作者:
Cuong Tran;Keyu Zhu;Ferdinando Fioretto;P. V. Hentenryck
Cuong Tran;Keyu Zhu;Ferdinando Fioretto;P. V. Hentenryck
中科院分区:
其他
文献类型:
--
作者:
Cuong Tran;Keyu Zhu;Ferdinando Fioretto;P. V. Hentenryck

文献摘要

相似文献

深度学习模型及其在相应领域(例如面部识别)的应用的卓越性能在公平和安全的交叉点引入了重要的挑战。公平性和健壮性是学习模型中经常需要的两个理想概念。公平性确保模型不会对某些群体造成不成比例的伤害(或使某些群体受益),而鲁棒性衡量模型对小输入扰动的恢复能力。本文证明了公平性与鲁棒性之间存在二分法,并分析了当实现公平性时会降低模型对对抗样本的鲁棒性。报告的分析揭示了导致这种对比行为的因素,表明跨群体与决策边界的距离是这种行为的关键解释。在非线性模型和不同结构上的大量实验验证了该理论在多个视觉领域的发现。最后,本文提出了一种简单而有效的方法来构建在公平性和鲁棒性之间取得良好平衡的模型。
The remarkable performance of deep learning models and their applications in consequential domains (e.g., facial recognition) introduces important challenges at the intersection of equity and security. Fairness and robustness are two desired notions often required in learning models. Fairness ensures that models do not disproportionately harm (or ben-efit) some groups over others, while robustness measures the models’ resilience against small input perturbations. This paper shows the existence of a dichotomy between fairness and robustness, and analyzes when achieving fairness decreases the model robustness to adversarial samples. The reported analysis sheds light on the factors causing such contrasting behavior, suggesting that distance to the decision boundary across groups as a key explainer for this behavior. Extensive experiments on non-linear models and different architectures validate the theoretical findings in multiple vision domains. Finally, the paper proposes a simple, yet effective, solution to construct models achieving good tradeoffs between fairness and robustness.