Simpler Certified Radius Maximization by Propagating Covariances

04/13/2021
by   Xingjian Zhen, et al.
0

One strategy for adversarially training a robust model is to maximize its certified radius – the neighborhood around a given training sample for which the model's prediction remains unchanged. The scheme typically involves analyzing a "smoothed" classifier where one estimates the prediction corresponding to Gaussian samples in the neighborhood of each sample in the mini-batch, accomplished in practice by Monte Carlo sampling. In this paper, we investigate the hypothesis that this sampling bottleneck can potentially be mitigated by identifying ways to directly propagate the covariance matrix of the smoothed distribution through the network. To this end, we find that other than certain adjustments to the network, propagating the covariances must also be accompanied by additional accounting that keeps track of how the distributional moments transform and interact at each stage in the network. We show how satisfying these criteria yields an algorithm for maximizing the certified radius on datasets including Cifar-10, ImageNet, and Places365 while offering runtime savings on networks with moderate depth, with a small compromise in overall accuracy. We describe the details of the key modifications that enable practical use. Via various experiments, we evaluate when our simplifications are sensible, and what the key benefits and limitations are.

READ FULL TEXT
research
01/08/2020

MACER: Attack-free and Scalable Robust Training via Maximizing Certified Radius

Adversarial training is one of the most popular ways to learn robust mod...
research
12/21/2021

Input-Specific Robustness Certification for Randomized Smoothing

Although randomized smoothing has demonstrated high certified robustness...
research
05/07/2021

From Graph Centrality to Data Depth

Given a sample of points in a Euclidean space, we can define a notion of...
research
12/05/2017

A Neighborhood-Assisted Hotelling's T^2 Test for High-Dimensional Means

This paper aims to revive the classical Hotelling's T^2 test in the "lar...
research
10/15/2022

Unveiling the Sampling Density in Non-Uniform Geometric Graphs

A powerful framework for studying graphs is to consider them as geometri...
research
01/02/2018

A Machine Learning Approach to Adaptive Covariance Localization

Data assimilation plays a key role in large-scale atmospheric weather fo...
research
10/01/2020

Assessing Robustness of Text Classification through Maximal Safe Radius Computation

Neural network NLP models are vulnerable to small modifications of the i...

Please sign up or login with your details

Forgot password? Click here to reset