Can we have it all? On the Trade-off between Spatial and Adversarial Robustness of Neural Networks
arXiv:2002.11318
Abstract
(Non-)robustness of neural networks to small, adversarial pixel-wise perturbations, and as more recently shown, to even random spatial transformations (e.g., translations, rotations) entreats both theoretical and empirical understanding. Spatial robustness to random translations and rotations is commonly attained via equivariant models (e.g., StdCNNs, GCNNs) and training augmentation, whereas adversarial robustness is typically achieved by adversarial training. In this paper, we prove a quantitative trade-off between spatial and adversarial robustness in a simple statistical setting. We complement this empirically by showing that: (a) as the spatial robustness of equivariant models improves by training augmentation with progressively larger transformations, their adversarial robustness worsens progressively, and (b) as the state-of-the-art robust models are adversarially trained with progressively larger pixel-wise perturbations, their spatial robustness drops progressively. Towards achieving pareto-optimality in this trade-off, we propose a method based on curriculum learning that trains gradually on more difficult perturbations (both spatial and adversarial) to improve spatial and adversarial robustness simultaneously.
Accepted NeurIPS 2021. Preliminary version consisting early experimental results was presented in ICML 2018 Workshop on "Towards learning with limited labels: Equivariance, Invariance,and Beyond" as "Understanding Adversarial Robustness of Symmetric Networks"
References in corpus (12)
- Very Deep Convolutional Networks for Large-Scale Image Recognition
- On the Generalization of Equivariance and Convolution in Neural Networks to the Action of Compact Groups
- Exploring the Landscape of Spatial Robustness
- Spatially Transformed Adversarial Examples
- Natural Adversarial Examples
- Curriculum Learning by Transfer Learning: Theory and Experiments with Deep Networks
- advertorch v0.1: An Adversarial Robustness Toolbox based on PyTorch
- On The Power of Curriculum Learning in Training Deep Networks
- Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations
- Deep Scale-spaces: Equivariance Over Scale
- Scale equivariance in CNNs with vector fields
- Efficient Certification of Spatial Robustness