Is Robustness the Cost of Accuracy? - A Comprehensive Study on the Robustness of 18 Deep Image Classification Models

被引:183
|
作者
Su, Dong [1 ]
Zhang, Huan [2 ]
Chen, Hongge [3 ]
Yi, Jinfeng [4 ]
Chen, Pin-Yu [1 ]
Gao, Yupeng [1 ]
机构
[1] IBM Res, New York, NY 10598 USA
[2] Univ Calif Davis, Davis, CA 95616 USA
[3] MIT, Cambridge, MA 02139 USA
[4] JD AI Res, Beijing, Peoples R China
来源
关键词
Deep neural networks; Adversarial attacks; Robustness;
D O I
10.1007/978-3-030-01258-8_39
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The prediction accuracy has been the long-lasting and sole standard for comparing the performance of different image classification models, including the ImageNet competition. However, recent studies have highlighted the lack of robustness in well-trained deep neural networks to adversarial examples. Visually imperceptible perturbations to natural images can easily be crafted and mislead the image classifiers towards misclassification. To demystify the trade-offs between robustness and accuracy, in this paper we thoroughly benchmark 18 ImageNet models using multiple robustness metrics, including the distortion, success rate and transferability of adversarial examples between 306 pairs of models. Our extensive experimental results reveal several new insights: (1) linear scaling law - the empirical l(2) and l(infinity) distortion metrics scale linearly with the logarithm of classification error; (2) model architecture is a more critical factor to robustness than model size, and the disclosed accuracy-robustness Pareto frontier can be used as an evaluation criterion for ImageNet model designers; (3) for a similar network architecture, increasing network depth slightly improves robustness in l(infinity) distortion; (4) there exist models (in VGG family) that exhibit high adversarial transferability, while most adversarial examples crafted from one model can only be transferred within the same family. Experiment code is publicly available at https://github.com/huanzhang12/Adversarial_Survey.
引用
收藏
页码:644 / 661
页数:18
相关论文
共 50 条
  • [41] Adversarial Robustness on Image Classification With k-Means
    Omari, Rollin
    Kim, Junae
    Montague, Paul
    IEEE ACCESS, 2024, 12 : 28853 - 28859
  • [42] Edge enhancement improves adversarial robustness in image classification
    He, Lirong
    Ai, Qingzhong
    Lei, Yuqing
    Pan, Lili
    Ren, Yazhou
    Xu, Zenglin
    NEUROCOMPUTING, 2023, 518 : 122 - 132
  • [43] Measuring Robustness to Natural Distribution Shifts in Image Classification
    Taori, Rohan
    Dave, Achal
    Shankar, Vaishaal
    Carlini, Nicholas
    Recht, Benjamin
    Schmidt, Ludwig
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 33, NEURIPS 2020, 2020, 33
  • [44] Dealing with Robustness of Convolutional Neural Networks for Image Classification
    Arcaini, Paolo
    Bombarda, Andrea
    Bonfanti, Silvia
    Gargantini, Angelo
    2020 IEEE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE TESTING (AITEST), 2020, : 7 - 14
  • [45] Robustness of Deep Convolutional Neural Networks for Image Recognition
    Ulicny, Matej
    Lundstrom, Jens
    Byttner, Stefan
    INTELLIGENT COMPUTING SYSTEMS, 2016, 597 : 16 - 30
  • [46] ROBUSTNESS OF DEEP CONVOLUTIONAL NEURAL NETWORKS FOR IMAGE DEGRADATIONS
    Ghosh, Sanjukta
    Shet, Rohan
    Amon, Peter
    Hutter, Andreas
    Kaup, Andre
    2018 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2018, : 2916 - 2920
  • [47] Statistical Robustness Study for Kinetic Models
    Coetzer, Roelof L. J.
    Engelbrecht, J. Pirow
    Crause, J. Christo
    Lin, Dennis K. J.
    INDUSTRIAL & ENGINEERING CHEMISTRY RESEARCH, 2010, 49 (06) : 2932 - 2942
  • [48] Robustness Study of Deep Learning Based Medical Image Segmentation to Noisy Annotation
    Yu, S.
    Zhang, E.
    Wu, J.
    Yu, H.
    Ma, L.
    Yang, Z.
    Chen, M.
    Gu, X.
    Lu, W.
    MEDICAL PHYSICS, 2020, 47 (06) : E657 - E657
  • [49] Robustness study of noisy annotation in deep learning based medical image segmentation
    Yu, Shaode
    Chen, Mingli
    Zhang, Erlei
    Wu, Junjie
    Yu, Hang
    Yang, Zi
    Ma, Lin
    Gu, Xuejun
    Lu, Weiguo
    PHYSICS IN MEDICINE AND BIOLOGY, 2020, 65 (17):
  • [50] ON THE ACCURACY AND ROBUSTNESS OF DEEP TRIPLET EMBEDDING FOR FINGERPRINT LIVENESS DETECTION
    Pala, Federico
    Bhanu, Bir
    2017 24TH IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2017, : 116 - 120