Opportunities and Challenges in Deep Learning Adversarial Robustness: A Survey
arXiv:2007.00753
Abstract
As we seek to deploy machine learning models beyond virtual and controlled domains, it is critical to analyze not only the accuracy or the fact that it works most of the time, but if such a model is truly robust and reliable. This paper studies strategies to implement adversary robustly trained algorithms towards guaranteeing safety in machine learning algorithms. We provide a taxonomy to classify adversarial attacks and defenses, formulate the Robust Optimization problem in a min-max setting and divide it into 3 subcategories, namely: Adversarial (re)Training, Regularization Approach, and Certified Defenses. We survey the most recent and important results in adversarial example generation, defense mechanisms with adversarial (re)Training as their main defense against perturbations. We also survey mothods that add regularization terms that change the behavior of the gradient, making it harder for attackers to achieve their objective. Alternatively, we've surveyed methods which formally derive certificates of robustness by exactly solving the optimization problem or by approximations using upper or lower bounds. In addition, we discuss the challenges faced by most of the recent algorithms presenting future research perspectives.
20 pages, 9 figures, submited to IEEE Transactions on Knowledge and Data Engineering
References in corpus (14)
- PyTorch: An Imperative Style, High-Performance Deep Learning Library
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Towards Deep Neural Network Architectures Robust to Adversarial Examples
- Opportunities and Challenges in Explainable Artificial Intelligence (XAI): A Survey
- Fast is better than free: Revisiting adversarial training
- Improving the Adversarial Robustness and Interpretability of Deep Neural Networks by Regularizing their Input Gradients
- Evaluating the Robustness of Neural Networks: An Extreme Value Theory Approach
- UPSET and ANGRI : Breaking High Performance Image Classifiers
- Metric Learning for Adversarial Robustness
- Robust Decision Trees Against Adversarial Examples
- Triple Wins: Boosting Accuracy, Robustness and Efficiency Together by Enabling Input-Adaptive Inference
- Fooling a Real Car with Adversarial Traffic Signs
- EMPIR: Ensembles of Mixed Precision Deep Networks for Increased Robustness against Adversarial Attacks
- An Adaptive View of Adversarial Robustness from Test-time Smoothing Defense