A Survey on Assessing the Generalization Envelope of Deep Neural Networks: Predictive Uncertainty, Out-of-distribution and Adversarial Samples
arXiv:2008.09381
Abstract
Deep Neural Networks (DNNs) achieve state-of-the-art performance on numerous applications. However, it is difficult to tell beforehand if a DNN receiving an input will deliver the correct output since their decision criteria are usually nontransparent. A DNN delivers the correct output if the input is within the area enclosed by its generalization envelope. In this case, the information contained in the input sample is processed reasonably by the network. It is of large practical importance to assess at inference time if a DNN generalizes correctly. Currently, the approaches to achieve this goal are investigated in different problem set-ups rather independently from one another, leading to three main research and literature fields: predictive uncertainty, out-of-distribution detection and adversarial example detection. This survey connects the three fields within the larger framework of investigating the generalization performance of machine learning methods and in particular DNNs. We underline the common ground, point at the most promising approaches and give a structured overview of the methods that provide at inference time means to establish if the current input is within the generalization envelope of a DNN.
References in corpus (17)
- On Calibration of Modern Neural Networks
- Weight Uncertainty in Neural Networks
- Deep Learning for Anomaly Detection: A Survey
- A Simple Unified Framework for Detecting Out-of-Distribution Samples and Adversarial Attacks
- Can You Trust Your Model's Uncertainty? Evaluating Predictive Uncertainty Under Dataset Shift
- Probabilistic Backpropagation for Scalable Learning of Bayesian Neural Networks
- Characterizing Adversarial Subspaces Using Local Intrinsic Dimensionality
- Adversarial Attacks and Defences: A Survey
- Adversarial Examples Are Not Bugs, They Are Features
- Deep k-Nearest Neighbors: Towards Confident, Interpretable and Robust Deep Learning
- Learning Confidence for Out-of-Distribution Detection in Neural Networks
- PixelDefend: Leveraging Generative Models to Understand and Defend against Adversarial Examples
- Defense-GAN: Protecting Classifiers Against Adversarial Attacks Using Generative Models
- To Trust Or Not To Trust A Classifier
- On Detecting Adversarial Perturbations
- Flipout: Efficient Pseudo-Independent Weight Perturbations on Mini-Batches
- Anomalous Example Detection in Deep Learning: A Survey