Adversarial Robustness with Partial Isometry

被引:1
|
作者
Shi-Garrier, Loic [1 ]
Bouaynaya, Nidhal Carla [2 ]
Delahaye, Daniel [1 ]
机构
[1] Univ Toulouse, ENAC, F-31400 Toulouse, France
[2] Rowan Univ, Dept Elect & Comp Engn, Glassboro, NJ 08028 USA
关键词
adversarial robustness; information geometry; fisher information metric; multi-class classification;
D O I
10.3390/e26020103
中图分类号
O4 [物理学];
学科分类号
0702 ;
摘要
Despite their remarkable performance, deep learning models still lack robustness guarantees, particularly in the presence of adversarial examples. This significant vulnerability raises concerns about their trustworthiness and hinders their deployment in critical domains that require certified levels of robustness. In this paper, we introduce an information geometric framework to establish precise robustness criteria for l2 white-box attacks in a multi-class classification setting. We endow the output space with the Fisher information metric and derive criteria on the input-output Jacobian to ensure robustness. We show that model robustness can be achieved by constraining the model to be partially isometric around the training points. We evaluate our approach using MNIST and CIFAR-10 datasets against adversarial attacks, revealing its substantial improvements over defensive distillation and Jacobian regularization for medium-sized perturbations and its superior robustness performance to adversarial training for large perturbations, all while maintaining the desired accuracy.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] On Isometry Robustness of Deep 3D Point Cloud Models under Adversarial Attacks
    Zhao, Yue
    Wu, Yuwei
    Chen, Caihua
    Lim, Andrew
    2020 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2020, : 1198 - 1207
  • [2] On Algebras Generated by a Partial Isometry
    Shi, Luoyi
    Zhu, Sen
    COMPLEX ANALYSIS AND OPERATOR THEORY, 2019, 13 (08) : 3825 - 3835
  • [3] THE C*-ALGEBRA OF A PARTIAL ISOMETRY
    Brenken, Berndt
    Niu, Zhuang
    PROCEEDINGS OF THE AMERICAN MATHEMATICAL SOCIETY, 2012, 140 (01) : 199 - 206
  • [4] Improving Adversarial Robustness With Adversarial Augmentations
    Chen, Chuanxi
    Ye, Dengpan
    He, Yiheng
    Tang, Long
    Xu, Yue
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (03) : 5105 - 5117
  • [5] On Algebras Generated by a Partial Isometry
    Luoyi Shi
    Sen Zhu
    Complex Analysis and Operator Theory, 2019, 13 : 3825 - 3835
  • [6] Adversarial Robustness for Code
    Bielik, Pavol
    Vechev, Martin
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 119, 2020, 119
  • [7] Adversarial Robustness Curves
    Goepfert, Christina
    Goepfert, Jan Philip
    Hammer, Barbara
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2019, PT I, 2020, 1167 : 172 - 179
  • [8] The Adversarial Robustness of Sampling
    Ben-Eliezer, Omri
    Yogev, Eylon
    PODS'20: PROCEEDINGS OF THE 39TH ACM SIGMOD-SIGACT-SIGAI SYMPOSIUM ON PRINCIPLES OF DATABASE SYSTEMS, 2020, : 49 - 62
  • [9] Adversarial attacks and adversarial robustness in computational pathology
    Narmin Ghaffari Laleh
    Daniel Truhn
    Gregory Patrick Veldhuizen
    Tianyu Han
    Marko van Treeck
    Roman D. Buelow
    Rupert Langer
    Bastian Dislich
    Peter Boor
    Volkmar Schulz
    Jakob Nikolas Kather
    Nature Communications, 13
  • [10] Adversarial attacks and adversarial robustness in computational pathology
    Ghaffari Laleh, Narmin
    Truhn, Daniel
    Veldhuizen, Gregory Patrick
    Han, Tianyu
    van Treeck, Marko
    Buelow, Roman D.
    Langer, Rupert
    Dislich, Bastian
    Boor, Peter
    Schulz, Volkmar
    Kather, Jakob Nikolas
    NATURE COMMUNICATIONS, 2022, 13 (01)