Affine-Invariant Robust Training

10/08/2020
by   Oriol Barbany Mayor, et al.
0

The field of adversarial robustness has attracted significant attention in machine learning. Contrary to the common approach of training models that are accurate in average case, it aims at training models that are accurate for worst case inputs, hence it yields more robust and reliable models. Put differently, it tries to prevent an adversary from fooling a model. The study of adversarial robustness is largely focused on ℓ_p-bounded adversarial perturbations, i.e. modifications of the inputs, bounded in some ℓ_p norm. Nevertheless, it has been shown that state-of-the-art models are also vulnerable to other more natural perturbations such as affine transformations, which were already considered in machine learning within data augmentation. This project reviews previous work in spatial robustness methods and proposes evolution strategies as zeroth order optimization algorithms to find the worst affine transforms for each input. The proposed method effectively yields robust models and allows introducing non-parametric adversarial perturbations.

READ FULL TEXT
research
11/05/2020

Data Augmentation via Structured Adversarial Perturbations

Data augmentation is a major component of many machine learning methods ...
research
05/04/2020

Robust Encodings: A Framework for Combating Adversarial Typos

Despite excellent performance on many tasks, NLP systems are easily fool...
research
09/24/2018

Is Ordered Weighted ℓ_1 Regularized Regression Robust to Adversarial Perturbation? A Case Study on OSCAR

Many state-of-the-art machine learning models such as deep neural networ...
research
03/08/2022

Towards Efficient Data-Centric Robust Machine Learning with Noise-based Augmentation

The data-centric machine learning aims to find effective ways to build a...
research
04/04/2023

Robustness Benchmark of Road User Trajectory Prediction Models for Automated Driving

Accurate and robust trajectory predictions of road users are needed to e...
research
05/13/2019

Affine Variational Autoencoders: An Efficient Approach for Improving Generalization and Robustness to Distribution Shift

In this study, we propose the Affine Variational Autoencoder (AVAE), a v...
research
11/29/2019

Adversarially Robust Low Dimensional Representations

Adversarial or test time robustness measures the susceptibility of a mac...

Please sign up or login with your details

Forgot password? Click here to reset