REVIEW 4 cited by
Adversarial Robustness May Be at Odds With Simplicity
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
abstract
Current techniques in machine learning are so far are unable to learn classifiers that are robust to adversarial perturbations. However, they are able to learn non-robust classifiers with very high accuracy, even in the presence of random perturbations. Towards explaining this gap, we highlight the hypothesis that $\textit{robust classification may require more complex classifiers (i.e. more capacity) than standard classification.}$ In this note, we show that this hypothesis is indeed possible, by giving several theoretical examples of classification tasks and sets of "simple" classifiers for which: (1) There exists a simple classifier with high standard accuracy, and also high accuracy under random $\ell_\infty$ noise. (2) Any simple classifier is not robust: it must have high adversarial loss with $\ell_\infty$ perturbations. (3) Robust classification is possible, but only with more complex classifiers (exponentially more complex, in some examples). Moreover, $\textit{there is a quantitative trade-off between robustness and standard accuracy among simple classifiers.}$ This suggests an alternate explanation of this phenomenon, which appears in practice: the tradeoff may occur not because the classification task inherently requires such a tradeoff (as in [Tsipras-Santurkar-Engstrom-Turner-Madry `18]), but because the structure of our current classifiers imposes such a tradeoff.
Forward citations
Cited by 4 Pith papers
-
Adversarial Training from Mean Field Perspective
A mean field framework for random ReLU networks yields adversarial-loss bounds and predicts that adversarial training shrinks weights, hurts vanilla depth, and is rescued by residual connections and width.
-
Nearly Tight Bounds for Robust Proper Learning of Halfspaces with a Margin
Constant-factor approximate proper learning of large-margin halfspaces is essentially settled: an optimal-sample 2^{Õ(1/γ²)}-time learner, plus an ETH-based 2^{(1/γ)^{2-o(1)}} runtime barrier for any proper learner.
-
Adversarially Robust Spiking Neural Networks with Sparse Connectivity
A conversion pipeline turns robustly trained, pruned artificial networks into sparse spiking networks that keep adversarial robustness and cut stored weights by up to 100x.
-
Intriguing Properties of Robust Classification
A new no-free-lunch construction and empirical scaling study argue that robust classification can require exponentially more data than standard classification, and that dataset size largely drives certified robust accuracy.
Discussion (0). Continue with ORCID to comment.