Shift Invariance Can Reduce Adversarial Robustness
arXiv:2103.02695
Abstract
Shift invariance is a critical property of CNNs that improves performance on classification. However, we show that invariance to circular shifts can also lead to greater sensitivity to adversarial attacks. We first characterize the margin between classes when a shift-invariant linear classifier is used. We show that the margin can only depend on the DC component of the signals. Then, using results about infinitely wide networks, we show that in some simple cases, fully connected and shift-invariant neural networks produce linear decision boundaries. Using this, we prove that shift invariance in neural networks produces adversarial examples for the simple case of two classes, each consisting of a single image with a black or white dot on a gray background. This is more than a curiosity; we show empirically that with real datasets and realistic architectures, shift invariance reduces adversarial robustness. Finally, we describe initial experiments using synthetic data to probe the source of this connection.
Published as a conference paper at NeurIPS 2021
References in corpus (13)
- Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms
- One weird trick for parallelizing convolutional neural networks
- On Exact Computation with an Infinitely Wide Neural Net
- Making Convolutional Networks Shift-Invariant Again
- Graph Neural Tangent Kernel: Fusing Graph Neural Networks with Graph Kernels
- The Convergence Rate of Neural Networks for Learned Functions of Different Frequencies
- Enhanced Convolutional Neural Tangent Kernels
- Adversarial Robustness May Be at Odds With Simplicity
- A Simple Explanation for the Existence of Adversarial Examples with Small Hamming Distance
- Batch Normalization is a Cause of Adversarial Vulnerability
- Tensor Programs II: Neural Tangent Kernel for Any Architecture
- Do Wider Neural Networks Really Help Adversarial Robustness?
- Mind the Pad -- CNNs can Develop Blind Spots