High Dimensional Spaces, Deep Learning and Adversarial Examples
arXiv:1801.00634
Abstract
In this paper, we analyze deep learning from a mathematical point of view and derive several novel results. The results are based on intriguing mathematical properties of high dimensional spaces. We first look at perturbation based adversarial examples and show how they can be understood using topological and geometrical arguments in high dimensions. We point out mistake in an argument presented in prior published literature, and we present a more rigorous, general and correct mathematical result to explain adversarial examples in terms of topology of image manifolds. Second, we look at optimization landscapes of deep neural networks and examine the number of saddle points relative to that of local minima. Third, we show how multiresolution nature of images explains perturbation based adversarial examples in form of a stronger result. Our results state that expectation of -norm of adversarial perturbations is and therefore shrinks to 0 as image resolution becomes arbitrarily large. Finally, by incorporating the parts-whole manifold learning hypothesis for natural images, we investigate the working of deep neural networks and root causes of adversarial examples and discuss how future improvements can be made and how adversarial examples can be eliminated.
29 pages, 15 figures
References in corpus (6)
- Explaining and Harnessing Adversarial Examples
- Characterizing Adversarial Subspaces Using Local Intrinsic Dimensionality
- Identifying and attacking the saddle point problem in high-dimensional non-convex optimization
- Large Deviations of Extreme Eigenvalues of Random Matrices
- Measuring the tendency of CNNs to Learn Surface Statistical Regularities
- A Boundary Tilting Persepective on the Phenomenon of Adversarial Examples
Cited by in corpus (8)
- Explaining Explanations in AI
- Characterizing the Decision Boundary of Deep Neural Networks
- Adequate and fair explanations
- Adversarial Training Versus Weight Decay
- Predicting Adversarial Examples with High Confidence
- A mathematical theory of imperfect communication: Energy efficiency considerations in multi-level coding
- A novel network training approach for open set image recognition
- Spatially Correlated Patterns in Adversarial Images