vix.ing · top · new · best · stats

A Theoretical Framework for Robustness of (Deep) Classifiers against Adversarial Examples

2016/12/01 by Beilun Wang, Wang, Beilun, Ji Gao +3 · 6 citations
Computer Science · #Advanced Malware Detection Techniques #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #cs.CR #cs.CV #cs.LG

paper · pdf · doi:10.48550/arxiv.1612.00334

38 pages , ICLR 2017 Workshop Track

arxiv created 2017/09/27 · arxiv updated 2017/09/28

Abstract

Most machine learning classifiers, including deep neural networks, are vulnerable to adversarial examples. Such inputs are typically generated by adding small but purposeful modifications that lead to incorrect outputs while imperceptible to human eyes. The goal of this paper is not to introduce a single method, but to make theoretical steps towards fully understanding adversarial examples. By using concepts from topology, our theoretical analysis brings forth the key reasons why an adversarial example can fool a classifier (f1) and adds its oracle (f2, like human eyes) in such analysis. By investigating the topological relationship between two (pseudo)metric spaces corresponding to predictor f1 and oracle f2, we develop necessary and sufficient conditions that can determine if f1 is always robust (strong-robust) against adversarial examples according to f2. Interestingly our theorems indicate that just one unnecessary feature can make f1 not strong-robust, and the right feature representation learning is the key to getting a classifier that is both accurate and strong-robust.

Citations

Cited by

Related