Understanding the Intrinsic Robustness of Image Distributions using Conditional Generative Models

Understanding the Intrinsic Robustness of Image Distributions using Conditional Generative Models
复制标题

DOI:
--
复制
发表时间:
2020-03
期刊:
--
影响因子:
--
通讯作者:
Xiao Zhang;Jinghui Chen;Quanquan Gu;David Evans
Xiao Zhang;Jinghui Chen;Quanquan Gu;David Evans
中科院分区:
其他
文献类型:
--
作者:
Xiao Zhang;Jinghui Chen;Quanquan Gu;David Evans

文献摘要

相似文献

从吉尔默等人开始。 (2018),一些作品已经证明了基于对潜在输入概率空间的不同假设的对抗性示例的必然性。然而,目前尚不清楚这些结果是否适用于自然图像分布。在这项工作中,我们假设底层数据分布是由某些条件生成模型捕获的,并证明了一般类别分类器的内在鲁棒性界限,这解决了 Fawzi 等人中的一个开放问题。 (2018)。基于最先进的条件生成模型,我们研究了两个常见图像基准在 $\ell_2$ 扰动下的内在鲁棒性,并表明我们的理论隐含的鲁棒性限制与当前最先进的鲁棒模型实现的对抗鲁棒性之间存在巨大差距。我们所有实验的代码都可以在此 https URL 中找到。
Starting with Gilmer et al. (2018), several works have demonstrated the inevitability of adversarial examples based on different assumptions about the underlying input probability space. It remains unclear, however, whether these results apply to natural image distributions. In this work, we assume the underlying data distribution is captured by some conditional generative model, and prove intrinsic robustness bounds for a general class of classifiers, which solves an open problem in Fawzi et al. (2018). Building upon the state-of-the-art conditional generative models, we study the intrinsic robustness of two common image benchmarks under $\ell_2$ perturbations, and show the existence of a large gap between the robustness limits implied by our theory and the adversarial robustness achieved by current state-of-the-art robust models. Code for all our experiments is available at this https URL.