Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial Robustness

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Pal, Ambar, Sulam, Jeremias, Vidal, René
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916259495411712
author Pal, Ambar
Sulam, Jeremias
Vidal, René
author_facet Pal, Ambar
Sulam, Jeremias
Vidal, René
contents The susceptibility of modern machine learning classifiers to adversarial examples has motivated theoretical results suggesting that these might be unavoidable. However, these results can be too general to be applicable to natural data distributions. Indeed, humans are quite robust for tasks involving vision. This apparent conflict motivates a deeper dive into the question: Are adversarial examples truly unavoidable? In this work, we theoretically demonstrate that a key property of the data distribution -- concentration on small-volume subsets of the input space -- determines whether a robust classifier exists. We further demonstrate that, for a data distribution concentrated on a union of low-dimensional linear subspaces, utilizing structure in data naturally leads to classifiers that enjoy data-dependent polyhedral robustness guarantees, improving upon methods for provable certification in certain regimes.
format Preprint
id arxiv_https___arxiv_org_abs_2309_16096
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial Robustness
Pal, Ambar
Sulam, Jeremias
Vidal, René
Machine Learning
Artificial Intelligence
The susceptibility of modern machine learning classifiers to adversarial examples has motivated theoretical results suggesting that these might be unavoidable. However, these results can be too general to be applicable to natural data distributions. Indeed, humans are quite robust for tasks involving vision. This apparent conflict motivates a deeper dive into the question: Are adversarial examples truly unavoidable? In this work, we theoretically demonstrate that a key property of the data distribution -- concentration on small-volume subsets of the input space -- determines whether a robust classifier exists. We further demonstrate that, for a data distribution concentrated on a union of low-dimensional linear subspaces, utilizing structure in data naturally leads to classifiers that enjoy data-dependent polyhedral robustness guarantees, improving upon methods for provable certification in certain regimes.
title Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial Robustness
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2309.16096