On Data Augmentation and Adversarial Risk: An Empirical Analysis

07/06/2020
by   Hamid Eghbal-zadeh, et al.
11

Data augmentation techniques have become standard practice in deep learning, as it has been shown to greatly improve the generalisation abilities of models. These techniques rely on different ideas such as invariance-preserving transformations (e.g, expert-defined augmentation), statistical heuristics (e.g, Mixup), and learning the data distribution (e.g, GANs). However, in the adversarial settings it remains unclear under what conditions such data augmentation methods reduce or even worsen the misclassification risk. In this paper, we therefore analyse the effect of different data augmentation techniques on the adversarial risk by three measures: (a) the well-known risk under adversarial attacks, (b) a new measure of prediction-change stress based on the Laplacian operator, and (c) the influence of training examples on prediction. The results of our empirical analysis disprove the hypothesis that an improvement in the classification performance induced by a data augmentation is always accompanied by an improvement in the risk under adversarial attack. Further, our results reveal that the augmented data has more influence than the non-augmented data, on the resulting models. Taken together, our results suggest that general-purpose data augmentations that do not take into the account the characteristics of the data and the task, must be applied with care.

READ FULL TEXT

page 13

page 17

research
05/29/2018

Improved Mixed-Example Data Augmentation

In order to reduce overfitting, neural networks are typically trained wi...
research
06/24/2021

On the (Un-)Avoidability of Adversarial Examples

The phenomenon of adversarial examples in deep learning models has cause...
research
09/03/2018

Data Augmentation for Neural Online Chat Response Selection

Data augmentation seeks to manipulate the available data for training to...
research
02/18/2022

Quantifying the Effects of Data Augmentation

We provide results that exactly quantify how data augmentation affects t...
research
02/20/2020

Affinity and Diversity: Quantifying Mechanisms of Data Augmentation

Though data augmentation has become a standard component of deep neural ...
research
02/15/2022

A Theory of PAC Learnability under Transformation Invariances

Transformation invariances are present in many real-world problems. For ...
research
08/20/2021

Mitigating Greenhouse Gas Emissions Through Generative Adversarial Networks Based Wildfire Prediction

Over the past decade, the number of wildfire has increased significantly...

Please sign up or login with your details

Forgot password? Click here to reset