Adversarial Robustness Guarantees for Gaussian Processes

04/07/2021
by   Andrea Patane, et al.
6

Gaussian processes (GPs) enable principled computation of model uncertainty, making them attractive for safety-critical applications. Such scenarios demand that GP decisions are not only accurate, but also robust to perturbations. In this paper we present a framework to analyse adversarial robustness of GPs, defined as invariance of the model's decision to bounded perturbations. Given a compact subset of the input space T⊆ℝ^d, a point x^* and a GP, we provide provable guarantees of adversarial robustness of the GP by computing lower and upper bounds on its prediction range in T. We develop a branch-and-bound scheme to refine the bounds and show, for any ϵ > 0, that our algorithm is guaranteed to converge to values ϵ-close to the actual values in finitely many iterations. The algorithm is anytime and can handle both regression and classification tasks, with analytical formulation for most kernels used in practice. We evaluate our methods on a collection of synthetic and standard benchmark datasets, including SPAM, MNIST and FashionMNIST. We study the effect of approximate inference techniques on robustness and demonstrate how our method can be used for interpretability. Our empirical results suggest that the adversarial robustness of GPs increases with accurate posterior estimation.

READ FULL TEXT

page 31

page 36

research
09/17/2018

Robustness Guarantees for Bayesian Inference with Gaussian Processes

Bayesian inference and Gaussian processes are widely used in application...
research
05/28/2019

Robustness Quantification for Classification with Gaussian Processes

We consider Bayesian classification with Gaussian processes (GPs) and de...
research
10/29/2018

Learning Gaussian Processes by Minimizing PAC-Bayesian Generalization Bounds

Gaussian Processes (GPs) are a generic modelling tool for supervised lea...
research
11/29/2019

Safety Guarantees for Planning Based on Iterative Gaussian Processes

Gaussian Processes (GPs) are widely employed in control and learning bec...
research
07/06/2023

Beyond Intuition, a Framework for Applying GPs to Real-World Data

Gaussian Processes (GPs) offer an attractive method for regression over ...
research
05/18/2023

Physics Inspired Approaches Towards Understanding Gaussian Processes

Prior beliefs about the latent function to shape inductive biases can be...
research
04/16/2018

Global Robustness Evaluation of Deep Neural Networks with Provable Guarantees for L0 Norm

Deployment of deep neural networks (DNNs) in safety or security-critical...

Please sign up or login with your details

Forgot password? Click here to reset