Canonical foliations of neural networks: application to robustness

03/02/2022
by   Eliot Tron, et al.
0

Adversarial attack is an emerging threat to the trustability of machine learning. Understanding these attacks is becoming a crucial task. We propose a new vision on neural network robustness using Riemannian geometry and foliation theory, and create a new adversarial attack by taking into account the curvature of the data space. This new adversarial attack called the "dog-leg attack" is a two-step approximation of a geodesic in the data space. The data space is treated as a (pseudo) Riemannian manifold equipped with the pullback of the Fisher Information Metric (FIM) of the neural network. In most cases, this metric is only semi-definite and its kernel becomes a central object to study. A canonical foliation is derived from this kernel. The curvature of the foliation's leaves gives the appropriate correction to get a two-step approximation of the geodesic and hence a new efficient adversarial attack. Our attack is tested on a toy example, a neural network trained to mimic the function, and demonstrates better results that the state of the art attack presented by Zhao et al. (2019).

READ FULL TEXT
research
04/29/2019

Information geometry and asymptotic geodesics on the space of normal distributions

The family N of n-variate normal distributions is parameterized by the c...
research
07/01/2019

Comment on "Adv-BNN: Improved Adversarial Defense through Robust Bayesian Neural Network"

A recent paper by Liu et al. combines the topics of adversarial training...
research
10/09/2018

The Adversarial Attack and Detection under the Fisher Information Metric

Many deep learning models are vulnerable to the adversarial attack, i.e....
research
04/17/2019

The Fisher-Rao geometry of beta distributions applied to the study of canonical moments

This paper studies the Fisher-Rao geometry on the parameter space of bet...
research
02/10/2018

Riemannian Manifold Kernel for Persistence Diagrams

Algebraic topology methods have recently played an important role for st...
research
07/16/2022

CARBEN: Composite Adversarial Robustness Benchmark

Prior literature on adversarial attack methods has mainly focused on att...
research
06/21/2022

Riemannian data-dependent randomized smoothing for neural networks certification

Certification of neural networks is an important and challenging problem...

Please sign up or login with your details

Forgot password? Click here to reset