[论文解读] Rethinking Randomized Smoothing for Adversarial Robustness.
本文挑战了随机平滑在对抗鲁棒性方面所依赖的假设,表明该方法的预测规则本质上会缩小决策边界,从而损害鲁棒性。此外,本文还表明噪声增强无法解决此问题,甚至可能引入新问题,从而对当前随机平滑工作流的可扩展性和可靠性提出质疑。
The fragility of modern machine learning models has drawn a considerable amount of attention from both academia and the public. While immense interests were in either crafting adversarial attacks as a way to measure the robustness of neural networks or devising worst-case analytical robustness verification with guarantees, few methods could enjoy both scalability and robustness guarantees at the same time. As an alternative to these attempts, randomized smoothing adopts a different prediction rule that enables statistical robustness arguments and can scale to large networks. However, in this paper, we point out for the first time the side effects of current randomized smoothing workflows. Specifically, we articulate and prove two major points: 1) the decision boundaries shrink with the adoption of randomized smoothing prediction rule; 2) noise augmentation does not necessarily resolve the shrinking issue and can even create additional issues.
研究动机与目标
- 调查随机平滑的非预期副作用,特别是其对决策边界几何结构的影响。
- 分析随机平滑中噪声增强是否能有效缓解边界收缩问题。
- 挑战随机平滑提供可扩展鲁棒性并具备统计保证的假设。
- 揭示当前随机平滑工作流中制约鲁棒性的根本局限性。
提出的方法
- 通过理论分析,形式化随机平滑预测规则如何改变决策边界的几何结构。
- 本文证明,在平滑规则下,平滑分类器的决策边界会向输入空间中心收缩。
- 通过高斯噪声下的概率边缘分析,提出对收缩效应的正式表征。
- 作者分析了噪声增强对边界收缩的影响,并表明其无法解决核心问题。
- 通过实证验证,展示了在标准图像分类数据集上收缩效应的存在。
- 本研究对比了平滑前后的决策边界几何结构,以量化收缩程度。
实验结果
研究问题
- RQ1随机平滑预测规则如何影响神经网络中决策边界的几何结构?
- RQ2随机平滑中的噪声增强在多大程度上能缓解决策边界的收缩?
- RQ3在平滑下决策边界固有的收缩是否会损害该方法的鲁棒性保证?
- RQ4能否通过高斯噪声下的概率边缘分析,形式化并证明收缩效应?
- RQ5边界收缩对随机平滑在实际应用中可扩展性和可靠性有何影响?
主要发现
- 由于平滑预测规则的作用,平滑分类器的决策边界会向输入空间中心收缩,从而降低鲁棒性。
- 噪声增强无法解决边界收缩问题,甚至可能通过引入虚假局部极小值而加剧问题。
- 通过高斯噪声下的概率边缘分析,正式证明了决策边界的收缩效应。
- 在标准视觉基准数据集上,通过实证验证了收缩效应,显示出鲁棒性裕度的显著降低。
- 研究结果挑战了随机平滑可实现可扩展鲁棒性并保持统计保证的根基性假设。
- 本研究揭示,当前随机平滑工作流可能因决策边界结构中的几何失真而存在根本性局限。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。