Timezone: »
Shift invariance is a critical property of CNNs that improves performance on classification. However, we show that invariance to circular shifts can also lead to greater sensitivity to adversarial attacks. We first characterize the margin between classes when a shift-invariant {\em linear} classifier is used. We show that the margin can only depend on the DC component of the signals. Then, using results about infinitely wide networks, we show that in some simple cases, fully connected and shift-invariant neural networks produce linear decision boundaries. Using this, we prove that shift invariance in neural networks produces adversarial examples for the simple case of two classes, each consisting of a single image with a black or white dot on a gray background. This is more than a curiosity; we show empirically that with real datasets and realistic architectures, shift invariance reduces adversarial robustness. Finally, we describe initial experiments using synthetic data to probe the source of this connection.
Author Information
Vasu Singla (University of Maryland)
I am a 3rd year Grad Student at the University of Maryland, interested in adversarial robustness.
Songwei Ge (University of Maryland, College Park)
Basri Ronen (Weizmann Inst.)
David Jacobs (University of Maryland, USA)
More from the Same Authors
-
2022 : Learning with noisy labels using low-dimensional model trajectory »
Vasu Singla · Shuchin Aeron · Toshiaki Koike-Akino · Kieran Parsons · Matthew Brand · Ye Wang -
2022 Poster: Autoregressive Perturbations for Data Poisoning »
Pedro Sandoval-Segura · Vasu Singla · Jonas Geiping · Micah Goldblum · Tom Goldstein · David Jacobs -
2022 Poster: On the Spectral Bias of Convolutional Neural Tangent and Gaussian Process Kernels »
Amnon Geifman · Meirav Galun · David Jacobs · Basri Ronen -
2021 Poster: Robust Contrastive Learning Using Negative Samples with Diminished Semantics »
Songwei Ge · Shlok Mishra · Chun-Liang Li · Haohan Wang · David Jacobs -
2020 : Creative Sketch Generation »
Songwei Ge -
2020 Poster: On the Similarity between the Laplace and Neural Tangent Kernels »
Amnon Geifman · Abhay Yadav · Yoni Kasten · Meirav Galun · David Jacobs · Basri Ronen -
2020 Poster: Multiview Neural Surface Reconstruction by Disentangling Geometry and Appearance »
Lior Yariv · Yoni Kasten · Dror Moran · Meirav Galun · Matan Atzmon · Basri Ronen · Yaron Lipman -
2020 Spotlight: Multiview Neural Surface Reconstruction by Disentangling Geometry and Appearance »
Lior Yariv · Yoni Kasten · Dror Moran · Meirav Galun · Matan Atzmon · Basri Ronen · Yaron Lipman -
2019 : Poster Session 2 »
Mayur Saxena · Nicholas Frosst · Vivien Cabannes · Gene Kogan · Austin Dill · Anurag Sarkar · Joel Ruben Antony Moniz · Vibert Thio · Scott Sievert · Lia Coleman · Frederik De Bleser · Brian Quanz · Jonathon Kereliuk · Panos Achlioptas · Mohamed Elhoseiny · Songwei Ge · Aidan Gomez · Jamie Brew -
2019 : Coffee Break & Poster Session 1 »
Yan Zhang · Jonathon Hare · Adam Prugel-Bennett · Po Leung · Patrick Flaherty · Pitchaya Wiratchotisatian · Alessandro Epasto · Silvio Lattanzi · Sergei Vassilvitskii · Morteza Zadimoghaddam · Theja Tulabandhula · Fabian Fuchs · Adam Kosiorek · Ingmar Posner · William Hang · Anna Goldie · Sujith Ravi · Azalia Mirhoseini · Yuwen Xiong · Mengye Ren · Renjie Liao · Raquel Urtasun · Haici Zhang · Michele Borassi · Shengda Luo · Andrew Trapp · Geoffroy Dubourg-Felonneau · Yasmeen Kussad · Christopher Bender · Manzil Zaheer · Junier Oliva · Michał Stypułkowski · Maciej Zieba · Austin Dill · Chun-Liang Li · Songwei Ge · Eunsu Kang · Oiwi Parker Jones · Kelvin Ka Wing Wong · Joshua Payne · Yang Li · Azade Nazi · Erkut Erdem · Aykut Erdem · Kevin O'Connor · Juan J Garcia · Maciej Zamorski · Jan Chorowski · Deeksha Sinha · Harry Clifford · John W Cassidy -
2019 Poster: Learning Robust Global Representations by Penalizing Local Predictive Power »
Haohan Wang · Songwei Ge · Zachary Lipton · Eric Xing -
2019 Poster: The Convergence Rate of Neural Networks for Learned Functions of Different Frequencies »
Basri Ronen · David Jacobs · Yoni Kasten · Shira Kritchman -
2018 : Poster Session 1 »
Evan Casey · Colin A Raffel · Jonathan Simon · Juncheng Li · Robert Saunders · Petra Gemeinboeck · Eunsu Kang · Songwei Ge · Curtis Hawthorne · Anna Huang · Ting-Wei Su · Eric Chu · Memo Akten · Sonam Damani · Khyatti Gupta · Dilpreet Singh · Patrick Hutchings