Pith. sign in

REVIEW 2 cited by

Cross-Entropy Loss and Low-Rank Features Have Responsibility for Adversarial Examples

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1901.08360 v1 pith:UZVTAHXW submitted 2019-01-24 cs.LG stat.ML

classification cs.LGstat.ML
keywords trainingadversarialdatasetfeatureslosscross-entropydifferentialexamples
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

State-of-the-art neural networks are vulnerable to adversarial examples; they can easily misclassify inputs that are imperceptibly different than their training and test data. In this work, we establish that the use of cross-entropy loss function and the low-rank features of the training data have responsibility for the existence of these inputs. Based on this observation, we suggest that addressing adversarial examples requires rethinking the use of cross-entropy loss function and looking for an alternative that is more suited for minimization with low-rank features. In this direction, we present a training scheme called differential training, which uses a loss function defined on the differences between the features of points from opposite classes. We show that differential training can ensure a large margin between the decision boundary of the neural network and the points in the training dataset. This larger margin increases the amount of perturbation needed to flip the prediction of the classifier and makes it harder to find an adversarial example with small perturbations. We test differential training on a binary classification task with CIFAR-10 dataset and demonstrate that it radically reduces the ratio of images for which an adversarial example could be found -- not only in the training dataset, but in the test dataset as well.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Plug-and-Play DISep: Separating Dense Instances for Scene-to-Pixel Weakly-Supervised Change Detection in High-Resolution Remote Sensing Images

    cs.CV 2025-01 conditional novelty 6.0 of 10

    A plug-and-play module that separates merged changed instances in weakly-supervised change detection, improving accuracy across seven baselines and five datasets.

  2. A Restricted Black-box Adversarial Framework Towards Attacking Graph Embedding Models

    cs.SI 2019-08 conditional novelty 6.0 of 10

    GF-Attack shows that a single edge flip chosen from spectral graph-filter properties lowers classification accuracy of GCN, SGC, DeepWalk, and LINE in a black-box setting.

Pith tools