On the Adversarial Robustness of Robust Estimators

被引:4
|
作者
Lai, Lifeng [1 ]
Bayraktar, Erhan [2 ]
机构
[1] Univ Calif Davis, Dept Elect & Comp Engn, Davis, CA 95616 USA
[2] Univ Michigan, Dept Math, Ann Arbor, MI 48104 USA
基金
美国国家科学基金会;
关键词
Robustness; Estimation; Optimization; Principal component analysis; Data analysis; Neural networks; Sociology; Robust estimators; adversarial robustness; M-estimator; non-convex optimization;
D O I
10.1109/TIT.2020.2985966
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Motivated by recent data analytics applications, we study the adversarial robustness of robust estimators. Instead of assuming that only a fraction of the data points are outliers as considered in the classic robust estimation setup, in this paper, we consider an adversarial setup in which an attacker can observe the whole dataset and can modify all data samples in an adversarial manner so as to maximize the estimation error caused by his attack. We characterize the attacker's optimal attack strategy, and further introduce adversarial influence function (AIF) to quantify an estimator's sensitivity to such adversarial attacks. We provide an approach to characterize AIF for any given robust estimator, and then design optimal estimator that minimizes AIF, which implies it is least sensitive to adversarial attacks and hence is most robust against adversarial attacks. From this characterization, we identify a tradeoff between AIF (i.e., robustness against adversarial attack) and influence function, a quantity used in classic robust estimators to measure robustness against outliers, and design estimators that strike a desirable tradeoff between these two quantities.
引用
收藏
页码:5097 / 5109
页数:13
相关论文
共 50 条
  • [31] EXPLOITING DOUBLY ADVERSARIAL EXAMPLES FOR IMPROVING ADVERSARIAL ROBUSTNESS
    Byun, Junyoung
    Go, Hyojun
    Cho, Seungju
    Kim, Changick
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 1331 - 1335
  • [32] On the Convergence and Robustness of Adversarial Training
    Wang, Yisen
    Ma, Xingjun
    Bailey, James
    Yi, Jinfeng
    Zhou, Bowen
    Gu, Quanquan
    [J]. INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 97, 2019, 97
  • [33] Adversarial Robustness of Model Sets
    Megyeri, Istvan
    Hegedus, Istvan
    Jelasity, Mark
    [J]. 2020 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2020,
  • [34] Metric Learning for Adversarial Robustness
    Mao, Chengzhi
    Zhong, Ziyuan
    Yang, Junfeng
    Vondrick, Carl
    Ray, Baishakhi
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32
  • [35] Dropping Pixels for Adversarial Robustness
    Hosseini, Hossein
    Kannan, Sreeram
    Poovendran, Radha
    [J]. 2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS (CVPRW 2019), 2019, : 91 - 97
  • [36] On Saliency Maps and Adversarial Robustness
    Mangla, Puneet
    Singh, Vedant
    Balasubramanian, Vineeth N.
    [J]. MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2020, PT II, 2021, 12458 : 272 - 288
  • [37] On the Adversarial Robustness of Mixture of Experts
    Puigcerver, Joan
    Jenatton, Rodolphe
    Riquelme, Carlos
    Awasthi, Pranjal
    Bhojanapalli, Srinadh
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 35, NEURIPS 2022, 2022,
  • [38] Disentangling Adversarial Robustness and Generalization
    Stutz, David
    Hein, Matthias
    Schiele, Bernt
    [J]. 2019 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR 2019), 2019, : 6969 - 6980
  • [39] On the Effect of Pruning on Adversarial Robustness
    Jordao, Artur
    Pedrini, Helio
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION WORKSHOPS (ICCVW 2021), 2021, : 1 - 11
  • [40] Stratified Adversarial Robustness with Rejection
    Chen, Jiefeng
    Raghuram, Jayaram
    Choi, Jihye
    Wu, Xi
    Liang, Yingyu
    Jha, Somesh
    [J]. INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 202, 2023, 202