Theoretically Principled Trade-off between Robustness and Accuracy
arXiv:1901.08573
Abstract
We identify a trade-off between robustness and accuracy that serves as a guiding principle in the design of defenses against adversarial examples. Although this problem has been widely studied empirically, much remains unknown concerning the theory underlying this trade-off. In this work, we decompose the prediction error for adversarial examples (robust error) as the sum of the natural (classification) error and boundary error, and provide a differentiable upper bound using the theory of classification-calibrated loss, which is shown to be the tightest possible upper bound uniform over all probability distributions and measurable predictors. Inspired by our theoretical analysis, we also design a new defense method, TRADES, to trade adversarial robustness off against accuracy. Our proposed algorithm performs well experimentally in real-world datasets. The methodology is the foundation of our entry to the NeurIPS 2018 Adversarial Vision Challenge in which we won the 1st place out of ~2,000 submissions, surpassing the runner-up approach by in terms of mean perturbation distance.
Appeared in ICML 2019; the winning methodology of the NeurIPS 2018 Adversarial Vision Challenge
References in corpus (2)
Cited by in corpus (14)
- Overfitting in adversarially robust deep learning
- MaxUp: A Simple Way to Improve Generalization of Neural Network Training
- Triple Wins: Boosting Accuracy, Robustness and Efficiency Together by Enabling Input-Adaptive Inference
- Bridging Adversarial Robustness and Gradient Interpretability
- Towards Compact and Robust Deep Neural Networks
- Attribution-driven Causal Analysis for Detection of Adversarial Examples
- Regularizers for Single-step Adversarial Training
- On Norm-Agnostic Robustness of Adversarial Training
- Robust binary classification with the 01 loss
- Robustness from Simple Classifiers
- Augmenting Model Robustness with Transformation-Invariant Attacks
- Understanding Adversarial Behavior of DNNs by Disentangling Non-Robust and Robust Components in Performance Metric
- Regularized Training and Tight Certification for Randomized Smoothed Classifier with Provable Robustness
- Graph Interpolating Activation Improves Both Natural and Robust Accuracies in Data-Efficient Deep Learning