Detecting Overfitting via Adversarial Examples
arXiv:1903.02380
Abstract
The repeated community-wide reuse of test sets in popular benchmark problems raises doubts about the credibility of reported test-error rates. Verifying whether a learned model is overfitted to a test set is challenging as independent test sets drawn from the same data distribution are usually unavailable, while other test sets may introduce a distribution shift. We propose a new hypothesis test that uses only the original test data to detect overfitting. It utilizes a new unbiased error estimate that is based on adversarial examples generated from the test data and importance weighting. Overfitting is detected if this error estimate is sufficiently different from the original test error rate. We develop a specialized variant of our test for multiclass image classification, and apply it to testing overfitting of recent models to the popular ImageNet benchmark. Our method correctly indicates overfitting of the trained model to the training set, but is not able to detect any overfitting to the test set, in line with other recent work on this topic.
17 pages
References in corpus (16)
- Google's Neural Machine Translation System: Bridging the Gap between Human and Machine Translation
- Ensemble Adversarial Training: Attacks and Defenses
- Towards Deep Learning Models Resistant to Adversarial Attacks
- Going Deeper with Convolutions
- Provable defenses against adversarial examples via the convex outer adversarial polytope
- Towards Deep Neural Network Architectures Robust to Adversarial Examples
- Do ImageNet Classifiers Generalize to ImageNet?
- Adversarial Risk and the Dangers of Evaluating Against Weak Attacks
- Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods
- Variational Approaches for Auto-Encoding Generative Adversarial Networks
- Why do deep convolutional networks generalize so poorly to small image transformations?
- On Adversarial Examples for Character-Level Neural Machine Translation
- Do CIFAR-10 Classifiers Generalize to CIFAR-10?
- Cold Case: The Lost MNIST Digits
- Defense against Adversarial Attacks Using High-Level Representation Guided Denoiser
- The advantages of multiple classes for reducing overfitting from test set reuse