Revisiting Adversarial Risk

被引:0
|
作者
Suggala, Arun Sai [1 ]
Prasad, Adarsh [1 ]
Nagarajan, Vaishnavh [1 ]
Ravikumar, Pradeep [1 ]
机构
[1] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
关键词
ROBUSTNESS;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recent works on adversarial perturbations show that there is an inherent trade-off between standard test accuracy and adversarial accuracy. Specifically, they show that no classifier can simultaneously be robust to adversarial perturbations and achieve high standard test accuracy. However, this is contrary to the standard notion that on tasks such as image classification, humans are robust classifiers with low error rate. In this work, we show that the main reason behind this confusion is the inexact definition of adversarial perturbation that is used in the literature. To fix this issue, we propose a slight, yet important modification to the existing definition of adversarial perturbation. Based on the modified definition, we show that there is no trade-off between adversarial and standard accuracies; there exist classifiers that are robust and achieve high standard accuracy. We further study several properties of this new definition of adversarial risk and its relation to the existing definition.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] Revisiting ensemble adversarial attack
    He, Ziwen
    Wang, Wei
    Dong, Jing
    Tan, Tieniu
    [J]. SIGNAL PROCESSING-IMAGE COMMUNICATION, 2022, 107
  • [2] Revisiting Residual Networks for Adversarial Robustness
    Huang, Shihua
    Lu, Zhichao
    Deb, Kalyanmoy
    Boddeti, Vishnu Naresh
    [J]. 2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 8202 - 8211
  • [3] REVISITING ROLE OF AUTOENCODERS IN ADVERSARIAL SETTINGS
    Kim, Byeong Cheon
    Kim, Jung Uk
    Lee, Hakmin
    Ro, Yong Man
    [J]. 2020 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2020, : 1856 - 1860
  • [4] Revisiting Outer Optimization in Adversarial Training
    Dabouei, Ali
    Taherkhani, Fariborz
    Soleymani, Sobhan
    Nasrabadi, Nasser M.
    [J]. COMPUTER VISION - ECCV 2022, PT V, 2022, 13665 : 244 - 261
  • [5] Revisiting model fairness via adversarial examples
    Zhang, Tao
    Zhu, Tianqing
    Li, Jing
    Zhou, Wanlei
    Yu, Philip S.
    [J]. KNOWLEDGE-BASED SYSTEMS, 2023, 277
  • [6] Adversarial classification: An adversarial risk analysis approach
    Naveiro, Roi
    Redondo, Alberto
    Insua, David Rios
    Ruggeri, Fabrizio
    [J]. INTERNATIONAL JOURNAL OF APPROXIMATE REASONING, 2019, 113 : 133 - 148
  • [7] Revisiting the transferability of adversarial examples via source-agnostic adversarial feature inducing method
    Xiao, Yatie
    Zhou, Jizhe
    Chen, Kongyang
    Liu, Zhenbang
    [J]. PATTERN RECOGNITION, 2023, 144
  • [8] Adversarial Risk Analysis
    Rios Insua, Insua
    Rios, Jesus
    Banks, David
    [J]. JOURNAL OF THE AMERICAN STATISTICAL ASSOCIATION, 2009, 104 (486) : 841 - 854
  • [10] Adversarial Risk Analysis
    Banks, David
    [J]. PROCEEDINGS OF THE 9TH ACM INTERNATIONAL WORKSHOP ON SECURITY AND PRIVACY ANALYTICS, IWSPA 2023, 2023, : 1 - 1