Manifold-driven decomposition for adversarial robustness

被引:0
|
作者
Zhang, Wenjia [1 ]
Zhang, Yikai [2 ]
Hu, Xiaoling [3 ]
Yao, Yi [4 ]
Goswami, Mayank [5 ]
Chen, Chao [6 ]
Metaxas, Dimitris [1 ]
机构
[1] Rutgers State Univ, Dept Comp Sci, Piscataway, NJ 08854 USA
[2] Morgan Stanley, New York, NY USA
[3] SUNY Stony Brook, Dept Comp Sci, Stony Brook, NY USA
[4] SRI Int, Comp Vis Lab, Princeton, NJ USA
[5] CUNY, Dept Comp Sci, Queens Coll, New York, NY USA
[6] SUNY Stony Brook, Dept Biomed Informat, Stony Brook, NY 11794 USA
来源
基金
美国国家科学基金会;
关键词
robustness; adversarial attack; manifold; topological analysis of network; generalization;
D O I
10.3389/fcomp.2023.1274695
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The adversarial risk of a machine learning model has been widely studied. Most previous studies assume that the data lie in the whole ambient space. We propose to take a new angle and take the manifold assumption into consideration. Assuming data lie in a manifold, we investigate two new types of adversarial risk, the normal adversarial risk due to perturbation along normal direction and the in-manifold adversarial risk due to perturbation within the manifold. We prove that the classic adversarial risk can be bounded from both sides using the normal and in-manifold adversarial risks. We also show a surprisingly pessimistic case that the standard adversarial risk can be non-zero even when both normal and in-manifold adversarial risks are zero. We finalize the study with empirical studies supporting our theoretical results. Our results suggest the possibility of improving the robustness of a classifier without sacrificing model accuracy, by only focusing on the normal adversarial risk.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] DAMPING OF THE MILKY WAY BAR BY MANIFOLD-DRIVEN SPIRALS
    Lokas, Ewa L.
    ASTROPHYSICAL JOURNAL LETTERS, 2016, 830 (01)
  • [2] Understanding adversarial robustness against on-manifold adversarial examples
    Xiao, Jiancong
    Yang, Liusha
    Fan, Yanbo
    Wang, Jue
    Luo, Zhi-Quan
    PATTERN RECOGNITION, 2025, 159
  • [3] Manifold-driven spirals in N-body barred galaxy simulations
    Athanassoula, E.
    MONTHLY NOTICES OF THE ROYAL ASTRONOMICAL SOCIETY, 2012, 426 (01) : L46 - L50
  • [4] Improving the Robustness of Model Compression by On-Manifold Adversarial Training
    Kwon, Junhyung
    Lee, Sangkyun
    FUTURE INTERNET, 2021, 13 (12)
  • [5] FedFusion: Manifold-Driven Federated Learning for Multi-Satellite and Multi-Modality Fusion
    Li, DaiXun
    Xie, Weiying
    Li, Yunsong
    Fang, Leyuan
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62 : 1 - 13
  • [6] Boost Off/On-Manifold Adversarial Robustness for Deep Learning with Latent Representation Mixup
    Huang, Mengdie
    Xie, Yi
    Chen, Xiaofeng
    Li, Jin
    Dong, Changyu
    Liu, Zheli
    Susilo, Willy
    PROCEEDINGS OF THE 2023 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ASIA CCS 2023, 2023, : 716 - 730
  • [7] Language-Driven Anchors for Zero-Shot Adversarial Robustness
    Li, Xiao
    Zhang, Wei
    Liu, Yining
    Hu, Zhanhao
    Zhang, Bo
    Hu, Xiaolin
    2024 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2024, : 24686 - 24695
  • [8] Propaganda Detection Robustness Through Adversarial Attacks Driven by eXplainable AI
    Cavaliere, Danilo
    Gallo, Mariacristina
    Stanzione, Claudio
    EXPLAINABLE ARTIFICIAL INTELLIGENCE, XAI 2023, PT II, 2023, 1902 : 405 - 419
  • [9] Adversarial Manifold Estimation
    Aamari, Eddie
    Knop, Alexander
    FOUNDATIONS OF COMPUTATIONAL MATHEMATICS, 2024, 24 (01) : 1 - 97
  • [10] Adversarial Manifold Estimation
    Eddie Aamari
    Alexander Knop
    Foundations of Computational Mathematics, 2024, 24 : 1 - 97