Is Robustness the Cost of Accuracy? - A Comprehensive Study on the Robustness of 18 Deep Image Classification Models

被引:183
|
作者
Su, Dong [1 ]
Zhang, Huan [2 ]
Chen, Hongge [3 ]
Yi, Jinfeng [4 ]
Chen, Pin-Yu [1 ]
Gao, Yupeng [1 ]
机构
[1] IBM Res, New York, NY 10598 USA
[2] Univ Calif Davis, Davis, CA 95616 USA
[3] MIT, Cambridge, MA 02139 USA
[4] JD AI Res, Beijing, Peoples R China
来源
关键词
Deep neural networks; Adversarial attacks; Robustness;
D O I
10.1007/978-3-030-01258-8_39
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The prediction accuracy has been the long-lasting and sole standard for comparing the performance of different image classification models, including the ImageNet competition. However, recent studies have highlighted the lack of robustness in well-trained deep neural networks to adversarial examples. Visually imperceptible perturbations to natural images can easily be crafted and mislead the image classifiers towards misclassification. To demystify the trade-offs between robustness and accuracy, in this paper we thoroughly benchmark 18 ImageNet models using multiple robustness metrics, including the distortion, success rate and transferability of adversarial examples between 306 pairs of models. Our extensive experimental results reveal several new insights: (1) linear scaling law - the empirical l(2) and l(infinity) distortion metrics scale linearly with the logarithm of classification error; (2) model architecture is a more critical factor to robustness than model size, and the disclosed accuracy-robustness Pareto frontier can be used as an evaluation criterion for ImageNet model designers; (3) for a similar network architecture, increasing network depth slightly improves robustness in l(infinity) distortion; (4) there exist models (in VGG family) that exhibit high adversarial transferability, while most adversarial examples crafted from one model can only be transferred within the same family. Experiment code is publicly available at https://github.com/huanzhang12/Adversarial_Survey.
引用
收藏
页码:644 / 661
页数:18
相关论文
共 50 条
  • [11] DeepAdversaries: examining the robustness of deep learning models for galaxy morphology classification
    Ciprijanovic, Aleksandra
    Kafkes, Diana
    Snyder, Gregory
    Sanchez, F. Javier
    Perdue, Gabriel Nathan
    Pedro, Kevin
    Nord, Brian
    Madireddy, Sandeep
    Wild, Stefan M.
    MACHINE LEARNING-SCIENCE AND TECHNOLOGY, 2022, 3 (03):
  • [12] Robustness Analysis for Deep Learning-Based Image Reconstruction Models
    Ayna, Cemre Omer
    Gurbuz, Ali Cafer
    2022 56TH ASILOMAR CONFERENCE ON SIGNALS, SYSTEMS, AND COMPUTERS, 2022, : 1428 - 1432
  • [13] Vine variety identification through leaf image classification: a large-scale study on the robustness of five deep learning models
    De Nart, D.
    Gardiman, M.
    Alba, V.
    Tarricone, L.
    Storchi, P.
    Roccotelli, S.
    Ammoniaci, M.
    Tosi, V.
    Perria, R.
    Carraro, R.
    JOURNAL OF AGRICULTURAL SCIENCE, 2024, 162 (01): : 19 - 32
  • [14] ON ADVERSARIAL ROBUSTNESS OF DEEP IMAGE DEBLURRING
    Gandikota, Kanchana Vaishnavi
    Chandramouli, Paramanand
    Moeller, Michael
    2022 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, ICIP, 2022, : 3161 - 3165
  • [15] Application of Ensemble Learning Techniques in Improving Accuracy and Robustness of Medical Classification Models
    Yang, Ruiyao
    PROCEEDINGS OF 2023 4TH INTERNATIONAL SYMPOSIUM ON ARTIFICIAL INTELLIGENCE FOR MEDICINE SCIENCE, ISAIMS 2023, 2023, : 1206 - 1211
  • [16] Contrastive JS']JS: A Novel Scheme for Enhancing the Accuracy and Robustness of Deep Models
    Xing, Weiwei
    Yao, Jie
    Liu, Zixia
    Liu, Weibin
    Zhang, Shunli
    Wang, Liqiang
    IEEE TRANSACTIONS ON MULTIMEDIA, 2023, 25 : 7881 - 7893
  • [17] A comprehensive evaluation framework for deep model robustness
    Guo, Jun
    Bao, Wei
    Wang, Jiakai
    Ma, Yuqing
    Gao, Xinghai
    Xiao, Gang
    Liu, Aishan
    Dong, Jian
    Liu, Xianglong
    Wu, Wenjun
    PATTERN RECOGNITION, 2023, 137
  • [18] ADVERSARIAL ROBUSTNESS OF DEEP LEARNING METHODS FOR SAR IMAGE CLASSIFICATION: AN EXPLAINABILITY VIEW
    Chen, Tianrui
    Wu, Juanping
    Guo, Weiwei
    Zhang, Zenghui
    IGARSS 2024-2024 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM, IGARSS 2024, 2024, : 1987 - 1991
  • [19] Accuracy and robustness of nonlinear eddy viscosity models
    Bauer, W
    Haag, O
    Hennecke, DK
    INTERNATIONAL JOURNAL OF HEAT AND FLUID FLOW, 2000, 21 (03) : 312 - 319
  • [20] A Review of Adversarial Robustness Evaluation for Image Classification
    Li, Zituo
    Sun, Jianbin
    Yang, Kewei
    Xiong, Dehui
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2022, 59 (10): : 2164 - 2189