On the Robustness of Randomized Ensembles to Adversarial Perturbations

02/02/2023
by   Hassan Dbouk, et al.
0

Randomized ensemble classifiers (RECs), where one classifier is randomly selected during inference, have emerged as an attractive alternative to traditional ensembling methods for realizing adversarially robust classifiers with limited compute requirements. However, recent works have shown that existing methods for constructing RECs are more vulnerable than initially claimed, casting major doubts on their efficacy and prompting fundamental questions such as: "When are RECs useful?", "What are their limits?", and "How do we train them?". In this work, we first demystify RECs as we derive fundamental results regarding their theoretical limits, necessary and sufficient conditions for them to be useful, and more. Leveraging this new understanding, we propose a new boosting algorithm (BARRE) for training robust RECs, and empirically demonstrate its effectiveness at defending against strong ℓ_∞ norm-bounded adversaries across various network architectures and datasets.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/14/2022

Adversarial Vulnerability of Randomized Ensembles

Despite the tremendous success of deep neural networks across various ta...
research
10/22/2018

Cost-Sensitive Robustness against Adversarial Examples

Several recent works have developed methods for training classifiers tha...
research
02/20/2023

Seasoning Model Soups for Robustness to Adversarial and Natural Distribution Shifts

Adversarial training is widely used to make classifiers robust to a spec...
research
02/17/2020

Regularized Training and Tight Certification for Randomized Smoothed Classifier with Provable Robustness

Recently smoothing deep neural network based classifiers via isotropic G...
research
10/30/2018

On the Effectiveness of Interval Bound Propagation for Training Verifiably Robust Models

Recent works have shown that it is possible to train models that are ver...
research
02/11/2022

Towards Adversarially Robust Deepfake Detection: An Ensemble Approach

Detecting deepfakes is an important problem, but recent work has shown t...
research
06/12/2019

A Stratified Approach to Robustness for Randomly Smoothed Classifiers

Strong theoretical guarantees of robustness can be given for ensembles o...

Please sign up or login with your details

Forgot password? Click here to reset