Similarity of Neural Architectures using Adversarial Attack Transferability

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hwang, Jaehui, Han, Dongyoon, Heo, Byeongho, Park, Song, Chun, Sanghyuk, Lee, Jong-Seok
Format: Preprint
Published: 2022
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916326602178560
author Hwang, Jaehui
Han, Dongyoon
Heo, Byeongho
Park, Song
Chun, Sanghyuk
Lee, Jong-Seok
author_facet Hwang, Jaehui
Han, Dongyoon
Heo, Byeongho
Park, Song
Chun, Sanghyuk
Lee, Jong-Seok
contents In recent years, many deep neural architectures have been developed for image classification. Whether they are similar or dissimilar and what factors contribute to their (dis)similarities remains curious. To address this question, we aim to design a quantitative and scalable similarity measure between neural architectures. We propose Similarity by Attack Transferability (SAT) from the observation that adversarial attack transferability contains information related to input gradients and decision boundaries widely used to understand model behaviors. We conduct a large-scale analysis on 69 state-of-the-art ImageNet classifiers using our proposed similarity function to answer the question. Moreover, we observe neural architecture-related phenomena using model similarity that model diversity can lead to better performance on model ensembles and knowledge distillation under specific conditions. Our results provide insights into why developing diverse neural architectures with distinct components is necessary.
format Preprint
id arxiv_https___arxiv_org_abs_2210_11407
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Similarity of Neural Architectures using Adversarial Attack Transferability
Hwang, Jaehui
Han, Dongyoon
Heo, Byeongho
Park, Song
Chun, Sanghyuk
Lee, Jong-Seok
Machine Learning
Computer Vision and Pattern Recognition
In recent years, many deep neural architectures have been developed for image classification. Whether they are similar or dissimilar and what factors contribute to their (dis)similarities remains curious. To address this question, we aim to design a quantitative and scalable similarity measure between neural architectures. We propose Similarity by Attack Transferability (SAT) from the observation that adversarial attack transferability contains information related to input gradients and decision boundaries widely used to understand model behaviors. We conduct a large-scale analysis on 69 state-of-the-art ImageNet classifiers using our proposed similarity function to answer the question. Moreover, we observe neural architecture-related phenomena using model similarity that model diversity can lead to better performance on model ensembles and knowledge distillation under specific conditions. Our results provide insights into why developing diverse neural architectures with distinct components is necessary.
title Similarity of Neural Architectures using Adversarial Attack Transferability
topic Machine Learning
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2210.11407