Relaxing Local Robustness

Relaxing Local Robustness
复制标题

DOI:
--
复制
发表时间:
2021-06
期刊:
--
影响因子:
--
通讯作者:
Klas Leino;Matt Fredrikson
Klas Leino;Matt Fredrikson
中科院分区:
其他
文献类型:
--
作者:
Klas Leino;Matt Fredrikson

文献摘要

被引文献

相似文献

可认证的局部鲁棒性严格排除了小范数对抗性示例,作为解决深度学习中安全问题的一种手段受到了极大的关注。然而,对于一些分类问题,局部鲁棒性并不是一个自然的目标,即使存在对手;例如,如果图像包含两类主题,则图像的正确标签可能被认为是任意的,因此没有必要对它们进行严格的分离。在这项工作中,我们为分类器引入了两个松弛的安全特性来解决这个问题:(1)松弛的top-k鲁棒性,它作为top-k精度的模拟;(2)亲和鲁棒性,它指定哪些标签集必须由鲁棒性边界分隔,哪些标签集可以在$\ell_p$空间中为$\epsilon$-close。我们展示了如何构建可以有效地针对每个松弛鲁棒性进行认证的模型,并以相对于标准梯度下降的很少开销进行训练。最后,我们通过实验证明,这些放松的鲁棒性变体非常适合于几个重要的分类问题,导致比认证“标准”局部鲁棒性时获得的更低的拒绝率和更高的认证精度。
Certifiable local robustness, which rigorously precludes small-norm adversarial examples, has received significant attention as a means of addressing security concerns in deep learning. However, for some classification problems, local robustness is not a natural objective, even in the presence of adversaries; for example, if an image contains two classes of subjects, the correct label for the image may be considered arbitrary between the two, and thus enforcing strict separation between them is unnecessary. In this work, we introduce two relaxed safety properties for classifiers that address this observation: (1) relaxed top-k robustness, which serves as the analogue of top-k accuracy; and (2) affinity robustness, which specifies which sets of labels must be separated by a robustness margin, and which can be $\epsilon$-close in $\ell_p$ space. We show how to construct models that can be efficiently certified against each relaxed robustness property, and trained with very little overhead relative to standard gradient descent. Finally, we demonstrate experimentally that these relaxed variants of robustness are well-suited to several significant classification problems, leading to lower rejection rates and higher certified accuracies than can be obtained when certifying"standard"local robustness.