2020/04/22 by Niklas Risse, Risse, Niklas, Christina Göpfert +3
Computer Science · #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #FOS: Computer and information sciences #Machine Learning (cs.LG) #Machine Learning (stat.ML)
paper · pdf · doi:10.48550/arxiv.2004.10882
openalex publication_date 2020/04/22 · openalex created_date 2022/09/19 · openalex updated_date 2026/07/28
Adversarial robustness of machine learning models has attracted considerable\nattention over recent years. Adversarial attacks undermine the reliability of\nand trust in machine learning models, but the construction of more robust\nmodels hinges on a rigorous understanding of adversarial robustness as a\nproperty of a given model. Point-wise measures for specific threat models are\ncurrently the most popular tool for comparing the robustness of classifiers and\nare used in most recent publications on adversarial robustness. In this work,\nwe use recently proposed robustness curves to show that point-wise measures\nfail to capture important global properties that are essential to reliably\ncompare the robustness of different classifiers. We introduce new ways in which\nrobustness curves can be used to systematically uncover these properties and\nprovide concrete recommendations for researchers and practitioners when\nassessing and comparing the robustness of trained models. Furthermore, we\ncharacterize scale as a way to distinguish small and large perturbations, and\nrelate it to inherent properties of data sets, demonstrating that robustness\nthresholds must be chosen accordingly. We release code to reproduce all\nexperiments presented in this paper, which includes a Python module to\ncalculate robustness curves for arbitrary data sets and classifiers, supporting\na number of frameworks, including TensorFlow, PyTorch and JAX.\n