Skip to main content
QUICK REVIEW

[論文レビュー] Adversarial Robustness Guarantees for Gaussian Processes

Andrea Patanè, Arno Blaas|arXiv (Cornell University)|Apr 7, 2021
Gaussian Processes and Bayesian Inference参考文献 44被引用数 4
ひとこと要約

本稿では、コンpactな入力集合上での予測範囲を束縛することにより、ガウス過程における証明可能な敵対的ロバスト性の保証を計算するための分岐・限定フレームワークを導入する。回帰および分類の両タスクにおいて $\epsilon$-正確な収束を保証し、一般的なカーネルに対して解析的境界を提示する。ロバスト性は事後分布推定の正確さに伴い向上することを示している。

ABSTRACT

Gaussian processes (GPs) enable principled computation of model uncertainty, making them attractive for safety-critical applications. Such scenarios demand that GP decisions are not only accurate, but also robust to perturbations. In this paper we present a framework to analyse adversarial robustness of GPs, defined as invariance of the model's decision to bounded perturbations. Given a compact subset of the input space $T\subseteq \mathbb{R}^d$, a point $x^*$ and a GP, we provide provable guarantees of adversarial robustness of the GP by computing lower and upper bounds on its prediction range in $T$. We develop a branch-and-bound scheme to refine the bounds and show, for any $ε> 0$, that our algorithm is guaranteed to converge to values $ε$-close to the actual values in finitely many iterations. The algorithm is anytime and can handle both regression and classification tasks, with analytical formulation for most kernels used in practice. We evaluate our methods on a collection of synthetic and standard benchmark datasets, including SPAM, MNIST and FashionMNIST. We study the effect of approximate inference techniques on robustness and demonstrate how our method can be used for interpretability. Our empirical results suggest that the adversarial robustness of GPs increases with accurate posterior estimation.

研究の動機と目的

  • 有界な入力摂動下におけるガウス過程の証明可能な敵対的ロバスト性の保証を提供すること。
  • 特にニューラルネットワークと比較して、GPモデルにおける正確なロバスト性解析の欠如に取り組むこと。
  • コンパクトな入力集合上での予測範囲の境界を計算するための、いつでも利用可能な $\epsilon$-収束アルゴリズムの開発。
  • 近似推論とハイパーパramータチューニングがGPのロバスト性に与える影響の評価。
  • 多様なデータセットにわたるロバスト性プロファイルの定量的評価を通じた解釈可能性の向上。

提案手法

  • フレームワークは、テスト点 $x^*$ を含むコンパクトな入力集合 $T \subseteq \mathbb{R}^d$ 上でのGP予測範囲の下限および上限を計算する。
  • 収束が $\epsilon$ の範囲内で終了するまで、反復的に境界を精緻化する分岐・限定スキームを採用する。
  • 各カーネルに対して、$\varphi(x,x')$ および $\psi(\varphi)$ 成分へのカーネル分解を用いて解析的境界関数を導出する。
  • 加法および乗法則をカーネル分解に適用し、スペクトル的および非定常形式を含む複雑なカーネルに対処する。
  • 境界関数は、$T$ 上での上界最適化を通じて計算され、線形および三角関数的性質を活用する。
  • アルゴリズムはいつでも有効な上界近似を提供する「いつでも利用可能(anytime)」であり、有限時間内で $\epsilon$-正確性を保証する。

実験結果

リサーチクエスチョン

  • RQ1有界な入力摂動下におけるガウス過程に対する証明可能な敵対的ロバスト性の保証は可能か?
  • RQ2事後分布推定の精度がGPモデルの敵対的ロバスト性にどのように影響するか?
  • RQ3期待値伝播(Expectation Propagation)のような近似推論手法は、ロバスト性保証をどの程度劣化させるか?
  • RQ4提案された分岐・限定フレームワークは、回帰および分類タスクの両方で、一般的なカーネルに対して解析的境界をサポートできるか?
  • RQ5SPAM、MNIST、Fashion-MNISTなどのデータセットにおいて、異なる推論手法下でのロバスト性プロファイルはどのように異なるか?

主な発見

  • 提案手法は、任意の $\epsilon > 0$ に対して、有限時間内で真の予測範囲極値に $\epsilon$-正確に収束することを保証する。
  • SPAM、MNIST、Fashion-MNISTの各データセットを通じて、GPモデルのロバスト性は事後分布推定の正確さに伴い向上することが示された。
  • 敵対的攻撃に基づくロバスト性推定は、本手法が摂動下での不変性を確認する領域を検出できない場合がある。
  • 平方指数カーネルおよび一般化スペクトルカーネルを含む一般的なカーネルに対して、解析的境界がサポートされる。
  • 期待値伝播は正確な推論と比較して低いロバスト性推定をもたらし、ロバスト性が推論品質に敏感であることが浮き彫りになった。
  • 本手法は、有界な摂動に対して予測が証明可能に不変である入力領域を特定できることから、解釈可能性を向上させる。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。