On the Coarse Robustness of Classifiers

On the Coarse Robustness of Classifiers
复制标题

DOI:
10.1109/ieeeconf56349.2022.10051990
复制
发表时间:
2022-10
期刊:
2022 56th Asilomar Conference on Signals, Systems, and Computers
影响因子:
--
通讯作者:
Ismail R. Alkhouri;Stanley Bak;Alvaro Velasquez;George K. Atia
Ismail R. Alkhouri;Stanley Bak;Alvaro Velasquez;George K. Atia
中科院分区:
其他
文献类型:
--
作者:
Ismail R. Alkhouri;Stanley Bak;Alvaro Velasquez;George K. Atia

文献摘要

相似文献

鲁棒性的标准度量,来源于最少量的对抗性扰动,通常不能衡量分类器识别粗类型的能力。对于与类语义一致的分组,希望有一个具有高粗鲁棒性的分类器,以便语义上合理的粗类别对难以察觉的扰动保持不变。在这项工作中,我们形式化了一个关于类标签的特定分组的粗糙鲁棒性的新概念。我们制定了一个优化问题,以获得最优分组,并开发了一种算法,显示出与蛮力搜索相当的性能。此外,我们提出了一种训练机制,该机制将粗标签信息和细标签信息结合在一起。我们的经验和理论表明,这种机制改进了所提出的粗糙鲁棒性概念,同时只需要相对较小的附加参数和训练时间。
Standard measures of robustness, derived from the least amount of adversarial perturbation, often fail to gauge the ability of a classifier to recognize the coarse genres. It is desirable to have a classifier with high coarse robustness with respect to a grouping that is consistent with the class semantics, so that semantically-plausible coarse categories remain invariant to imperceptible perturbations. In this work, we formalize a new notion of coarse robustness that is defined with respect to a specified grouping of the class labels. We formulate an optimization problem to obtain the optimal grouping, and develop an algorithm that is shown to perform on par with brute force search. Moreover, we propose a training mechanism that incorporates the coarse label information in addition to the finer ones. We empirically and theoretically show that this mechanism improves the proposed coarse notion of robustness while only requiring a relatively small additional parameters and training time.