Fairness Through Robustness: Investigating Robustness Disparity in Deep Learning

Fairness Through Robustness: Investigating Robustness Disparity in Deep Learning
复制标题

DOI:
10.1145/3442188.3445910
复制
发表时间:
2020-06
期刊:
Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency
影响因子:
--
通讯作者:
Vedant Nanda;Samuel Dooley;Sahil Singla;S. Feizi;John P. Dickerson
Vedant Nanda;Samuel Dooley;Sahil Singla;S. Feizi;John P. Dickerson
中科院分区:
其他
文献类型:
--
作者:
Vedant Nanda;Samuel Dooley;Sahil Singla;S. Feizi;John P. Dickerson

文献摘要

被引文献

相似文献

深度神经网络(dnn)越来越多地应用于现实世界(例如面部识别)。这导致了人们对这些模型所做决定的公正性的担忧。人们提出了各种关于公平的概念和措施,以确保决策制度不会不成比例地损害(或有利于)人口中的特定次群体。在本文中,我们认为,当模型容易受到对抗性攻击时,仅基于模型输出的传统公平概念是不够的。我们认为,在某些情况下,攻击者可能更容易瞄准特定的子组,从而导致某种形式的鲁棒性偏差。我们表明测量稳健性偏差对于dnn来说是一项具有挑战性的任务,并提出了两种方法来测量这种形式的偏差。然后,我们在常用的现实世界数据集(如CIFAR-10、CIFAR-100、Adience和UTKFace)上对最先进的神经网络进行了实证研究,并表明在几乎所有情况下,都有子组(在某些情况下基于种族、性别等敏感属性)鲁棒性较差,因此处于劣势。我们认为,在dnn的情况下,这种偏差是由于数据分布和学习决策边界的高度复杂性而产生的,因此减轻这种偏差是一项非平凡的任务。我们的研究结果表明,在审计依赖dnn进行决策的现实世界系统时,鲁棒性偏差是一个重要的考虑标准。复制所有结果的代码可以在这里找到:https://github.com/nvedant07/Fairness-Through-Robustness
Deep neural networks (DNNs) are increasingly used in real-world applications (e.g. facial recognition). This has resulted in concerns about the fairness of decisions made by these models. Various notions and measures of fairness have been proposed to ensure that a decision-making system does not disproportionately harm (or benefit) particular subgroups of the population. In this paper, we argue that traditional notions of fairness that are only based on models' outputs are not sufficient when the model is vulnerable to adversarial attacks. We argue that in some cases, it may be easier for an attacker to target a particular subgroup, resulting in a form of robustness bias. We show that measuring robustness bias is a challenging task for DNNs and propose two methods to measure this form of bias. We then conduct an empirical study on state-of-the-art neural networks on commonly used real-world datasets such as CIFAR-10, CIFAR-100, Adience, and UTKFace and show that in almost all cases there are subgroups (in some cases based on sensitive attributes like race, gender, etc) which are less robust and are thus at a disadvantage. We argue that this kind of bias arises due to both the data distribution and the highly complex nature of the learned decision boundary in the case of DNNs, thus making mitigation of such biases a non-trivial task. Our results show that robustness bias is an important criterion to consider while auditing real-world systems that rely on DNNs for decision making. Code to reproduce all our results can be found here: https://github.com/nvedant07/Fairness-Through-Robustness