Efficient Estimation of the Local Robustness of Machine Learning Models

07/26/2023
by   Tessa Han, et al.
0

Machine learning models often need to be robust to noisy input data. The effect of real-world noise (which is often random) on model predictions is captured by a model's local robustness, i.e., the consistency of model predictions in a local region around an input. However, the naïve approach to computing local robustness based on Monte-Carlo sampling is statistically inefficient, leading to prohibitive computational costs for large-scale applications. In this work, we develop the first analytical estimators to efficiently compute local robustness of multi-class discriminative models using local linear function approximation and the multivariate Normal CDF. Through the derivation of these estimators, we show how local robustness is connected to concepts such as randomized smoothing and softmax probability. We also confirm empirically that these estimators accurately and efficiently compute the local robustness of standard deep learning models. In addition, we demonstrate these estimators' usefulness for various tasks involving local robustness, such as measuring robustness bias and identifying examples that are vulnerable to noise perturbation in a dataset. By developing these analytical estimators, this work not only advances conceptual understanding of local robustness, but also makes its computation practical, enabling the use of local robustness in critical downstream applications.

READ FULL TEXT
research
04/21/2022

Robustness of Machine Learning Models Beyond Adversarial Attacks

Correctly quantifying the robustness of machine learning models is a cen...
research
06/06/2022

Certified Robustness in Federated Learning

Federated learning has recently gained significant attention and popular...
research
06/25/2019

Monte Carlo Gradient Estimation in Machine Learning

This paper is a broad and accessible survey of the methods we have at ou...
research
11/15/2020

Almost Tight L0-norm Certified Robustness of Top-k Predictions against Adversarial Perturbations

Top-k predictions are used in many real-world applications such as machi...
research
02/15/2022

Improving the repeatability of deep learning models with Monte Carlo dropout

The integration of artificial intelligence into clinical workflows requi...
research
10/18/2019

Center-Outward R-Estimation for Semiparametric VARMA Models

We propose a new class of estimators for semiparametric VARMA models wit...
research
06/29/2023

Group-based Robustness: A General Framework for Customized Robustness in the Real World

Machine-learning models are known to be vulnerable to evasion attacks th...

Please sign up or login with your details

Forgot password? Click here to reset