Mixing Classifiers to Alleviate the Accuracy-Robustness Trade-Off

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Bai, Yatong, Anderson, Brendon G., Sojoudi, Somayeh
Format: Preprint
Veröffentlicht: 2023
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866914821333581824
author Bai, Yatong
Anderson, Brendon G.
Sojoudi, Somayeh
author_facet Bai, Yatong
Anderson, Brendon G.
Sojoudi, Somayeh
contents Deep neural classifiers have recently found tremendous success in data-driven control systems. However, existing models suffer from a trade-off between accuracy and adversarial robustness. This limitation must be overcome in the control of safety-critical systems that require both high performance and rigorous robustness guarantees. In this work, we develop classifiers that simultaneously inherit high robustness from robust models and high accuracy from standard models. Specifically, we propose a theoretically motivated formulation that mixes the output probabilities of a standard neural network and a robust neural network. Both base classifiers are pre-trained, and thus our method does not require additional training. Our numerical experiments verify that the mixed classifier noticeably improves the accuracy-robustness trade-off and identify the confidence property of the robust base classifier as the key leverage of this more benign trade-off. Our theoretical results prove that under mild assumptions, when the robustness of the robust base model is certifiable, no alteration or attack within a closed-form $\ell_p$ radius on an input can result in the misclassification of the mixed classifier.
format Preprint
id arxiv_https___arxiv_org_abs_2311_15165
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Mixing Classifiers to Alleviate the Accuracy-Robustness Trade-Off
Bai, Yatong
Anderson, Brendon G.
Sojoudi, Somayeh
Machine Learning
Computer Vision and Pattern Recognition
68T07
Deep neural classifiers have recently found tremendous success in data-driven control systems. However, existing models suffer from a trade-off between accuracy and adversarial robustness. This limitation must be overcome in the control of safety-critical systems that require both high performance and rigorous robustness guarantees. In this work, we develop classifiers that simultaneously inherit high robustness from robust models and high accuracy from standard models. Specifically, we propose a theoretically motivated formulation that mixes the output probabilities of a standard neural network and a robust neural network. Both base classifiers are pre-trained, and thus our method does not require additional training. Our numerical experiments verify that the mixed classifier noticeably improves the accuracy-robustness trade-off and identify the confidence property of the robust base classifier as the key leverage of this more benign trade-off. Our theoretical results prove that under mild assumptions, when the robustness of the robust base model is certifiable, no alteration or attack within a closed-form $\ell_p$ radius on an input can result in the misclassification of the mixed classifier.
title Mixing Classifiers to Alleviate the Accuracy-Robustness Trade-Off
topic Machine Learning
Computer Vision and Pattern Recognition
68T07
url https://arxiv.org/abs/2311.15165