vix.ing · top · new · best · stats

Can we have it all? On the Trade-off between Spatial and Adversarial Robustness of Neural Networks

2020/02/26 by Sandesh Kamath, Amit Deshpande, Kamath, Sandesh +6 · 2 citations
Biochemistry, Genetics and Molecular Biology · Computer Science · Engineering · Mathematics · #Adversarial Robustness in Machine Learning #Bacillus and Francisella bacterial research #Computer Vision and Pattern Recognition (cs.CV) #FOS: Computer and information sciences #Integrated Circuits and Semiconductor Failure Analysis #Machine Learning (cs.LG) #Machine Learning (stat.ML) #Neural and Evolutionary Computing (cs.NE) #cs.CV #cs.LG #cs.NE #stat.ML

paper · pdf · doi:10.48550/arxiv.2002.11318

Accepted NeurIPS 2021. Preliminary version consisting early experimental results was presented in ICML 2018 Workshop on "Towards learning with limited labels: Equivariance, Invariance,and Beyond" as "Understanding Adversarial Robustness of Symmetric Networks"

openalex publication_date 2020/02/26 · arxiv created 2021/11/10 · arxiv updated 2021/11/11 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28

Abstract

(Non-)robustness of neural networks to small, adversarial pixel-wise perturbations, and as more recently shown, to even random spatial transformations (e.g., translations, rotations) entreats both theoretical and empirical understanding. Spatial robustness to random translations and rotations is commonly attained via equivariant models (e.g., StdCNNs, GCNNs) and training augmentation, whereas adversarial robustness is typically achieved by adversarial training. In this paper, we prove a quantitative trade-off between spatial and adversarial robustness in a simple statistical setting. We complement this empirically by showing that: (a) as the spatial robustness of equivariant models improves by training augmentation with progressively larger transformations, their adversarial robustness worsens progressively, and (b) as the state-of-the-art robust models are adversarially trained with progressively larger pixel-wise perturbations, their spatial robustness drops progressively. Towards achieving pareto-optimality in this trade-off, we propose a method based on curriculum learning that trains gradually on more difficult perturbations (both spatial and adversarial) to improve spatial and adversarial robustness simultaneously.

Citations

Cited by

Related