Timezone: »
This paper investigates the theory of robustness against adversarial attacks. It focuses on the family of randomization techniques that consist in injecting noise in the network at inference time. These techniques have proven effective in many contexts, but lack theoretical arguments. We close this gap by presenting a theo- retical analysis of these approaches, hence explaining why they perform well in practice. More precisely, we make two new contributions. The first one relates the randomization rate to robustness to adversarial attacks. This result applies for the general family of exponential distributions, and thus extends and unifies the previous approaches. The second contribution consists in devising a new upper bound on the adversarial risk gap of randomized neural networks. We support our theoretical claims with a set of experiments.
Author Information
Rafael Pinot (Dauphine University - CEA LIST Institute)
Laurent Meunier (Dauphine University - FAIR Paris)
Alexandre Araujo (Université Paris-Dauphine)
Hisashi Kashima (Kyoto University/RIKEN Center for AIP)
Florian Yger (Université Paris-Dauphine)
Cedric Gouy-Pailler (CEA)
Jamal Atif (Université Paris-Dauphine)
More from the Same Authors
-
2023 Poster: Regularizing Neural Networks with Meta-Learning Generative Models »
Shin'ya Yamaguchi · Daiki Chijiwa · Sekitoshi Kanai · Atsutoshi Kumagai · Hisashi Kashima -
2022 Poster: Towards Consistency in Adversarial Classification »
Laurent Meunier · Raphael Ettedgui · Rafael Pinot · Yann Chevaleyre · Jamal Atif -
2021 Poster: Two-sided fairness in rankings via Lorenz dominance »
Virginie Do · Sam Corbett-Davies · Jamal Atif · Nicolas Usunier -
2020 Poster: Fast Unbalanced Optimal Transport on a Tree »
Ryoma Sato · Makoto Yamada · Hisashi Kashima -
2020 Poster: Adversarial Attacks on Linear Contextual Bandits »
Evrard Garcelon · Baptiste Roziere · Laurent Meunier · Jean Tarbouriech · Olivier Teytaud · Alessandro Lazaric · Matteo Pirotta -
2019 Poster: Fast Sparse Group Lasso »
Yasutoshi Ida · Yasuhiro Fujiwara · Hisashi Kashima -
2019 Poster: Approximation Ratios of Graph Neural Networks for Combinatorial Problems »
Ryoma Sato · Makoto Yamada · Hisashi Kashima -
2018 Poster: Uplift Modeling from Separate Labels »
Ikko Yamane · Florian Yger · Jamal Atif · Masashi Sugiyama