Likelihood Landscapes: A Unifying Principle Behind Many Adversarial Defenses
arXiv:2008.11300
Abstract
Convolutional Neural Networks have been shown to be vulnerable to adversarial examples, which are known to locate in subspaces close to where normal data lies but are not naturally occurring and of low probability. In this work, we investigate the potential effect defense techniques have on the geometry of the likelihood landscape - likelihood of the input images under the trained model. We first propose a way to visualize the likelihood landscape leveraging an energy-based model interpretation of discriminative classifiers. Then we introduce a measure to quantify the flatness of the likelihood landscape. We observe that a subset of adversarial defense techniques results in a similar effect of flattening the likelihood landscape. We further explore directly regularizing towards a flat landscape for adversarial robustness.
ECCV 2020 Workshop on Adversarial Robustness in the Real World
References in corpus (6)
- Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms
- Theoretically Principled Trade-off between Robustness and Accuracy
- Towards Deep Neural Network Architectures Robust to Adversarial Examples
- Countering Adversarial Images using Input Transformations
- Improving the Adversarial Robustness and Interpretability of Deep Neural Networks by Regularizing their Input Gradients
- Qualitatively characterizing neural network optimization problems