Generalized Likelihood Ratio Test for Adversarially Robust Hypothesis Testing

12/04/2021
by   Bhagyashree Puranik, et al.
0

Machine learning models are known to be susceptible to adversarial attacks which can cause misclassification by introducing small but well designed perturbations. In this paper, we consider a classical hypothesis testing problem in order to develop fundamental insight into defending against such adversarial perturbations. We interpret an adversarial perturbation as a nuisance parameter, and propose a defense based on applying the generalized likelihood ratio test (GLRT) to the resulting composite hypothesis testing problem, jointly estimating the class of interest and the adversarial perturbation. While the GLRT approach is applicable to general multi-class hypothesis testing, we first evaluate it for binary hypothesis testing in white Gaussian noise under ℓ_∞ norm-bounded adversarial perturbations, for which a known minimax defense optimizing for the worst-case attack provides a benchmark. We derive the worst-case attack for the GLRT defense, and show that its asymptotic performance (as the dimension of the data increases) approaches that of the minimax defense. For non-asymptotic regimes, we show via simulations that the GLRT defense is competitive with the minimax approach under the worst-case attack, while yielding a better robustness-accuracy tradeoff under weaker attacks. We also illustrate the GLRT approach for a multi-class hypothesis testing problem, for which a minimax strategy is not known, evaluating its performance under both noise-agnostic and noise-aware adversarial settings, by providing a method to find optimal noise-aware attacks, and heuristics to find noise-agnostic attacks that are close to optimal in the high SNR regime.

READ FULL TEXT

page 1

page 9

research
11/16/2020

Adversarially Robust Classification based on GLRT

Machine learning models are vulnerable to adversarial attacks that can o...
research
04/03/2020

On Universality and Training in Binary Hypothesis Testing

The classical binary hypothesis testing problem is revisited. We notice ...
research
09/21/2020

Optimal Provable Robustness of Quantum Classification via Quantum Hypothesis Testing

Quantum machine learning models have the potential to offer speedups and...
research
10/14/2020

Linking average- and worst-case perturbation robustness via class selectivity and dimensionality

Representational sparsity is known to affect robustness to input perturb...
research
03/07/2023

Exploiting Trust for Resilient Hypothesis Testing with Malicious Robots (evolved version)

We develop a resilient binary hypothesis testing framework for decision ...
research
09/25/2022

Exploiting Trust for Resilient Hypothesis Testing with Malicious Robots

We develop a resilient binary hypothesis testing framework for decision ...
research
08/04/2022

CFARnet: deep learning for target detection with constant false alarm rate

We consider the problem of learning detectors with a Constant False Alar...

Please sign up or login with your details

Forgot password? Click here to reset