Boosting Certified Robustness for Time Series Classification with Efficient Self-Ensemble

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Dong, Chang, Li, Zhengyang, Zheng, Liangwei, Chen, Weitong, Zhang, Wei Emma
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910611886047232
author Dong, Chang
Li, Zhengyang
Zheng, Liangwei
Chen, Weitong
Zhang, Wei Emma
author_facet Dong, Chang
Li, Zhengyang
Zheng, Liangwei
Chen, Weitong
Zhang, Wei Emma
contents Recently, the issue of adversarial robustness in the time series domain has garnered significant attention. However, the available defense mechanisms remain limited, with adversarial training being the predominant approach, though it does not provide theoretical guarantees. Randomized Smoothing has emerged as a standout method due to its ability to certify a provable lower bound on robustness radius under $\ell_p$-ball attacks. Recognizing its success, research in the time series domain has started focusing on these aspects. However, existing research predominantly focuses on time series forecasting, or under the non-$\ell_p$ robustness in statistic feature augmentation for time series classification~(TSC). Our review found that Randomized Smoothing performs modestly in TSC, struggling to provide effective assurances on datasets with poor robustness. Therefore, we propose a self-ensemble method to enhance the lower bound of the probability confidence of predicted labels by reducing the variance of classification margins, thereby certifying a larger radius. This approach also addresses the computational overhead issue of Deep Ensemble~(DE) while remaining competitive and, in some cases, outperforming it in terms of robustness. Both theoretical analysis and experimental results validate the effectiveness of our method, demonstrating superior performance in robustness testing compared to baseline approaches.
format Preprint
id arxiv_https___arxiv_org_abs_2409_02802
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Boosting Certified Robustness for Time Series Classification with Efficient Self-Ensemble
Dong, Chang
Li, Zhengyang
Zheng, Liangwei
Chen, Weitong
Zhang, Wei Emma
Machine Learning
Cryptography and Security
H.3.3
Recently, the issue of adversarial robustness in the time series domain has garnered significant attention. However, the available defense mechanisms remain limited, with adversarial training being the predominant approach, though it does not provide theoretical guarantees. Randomized Smoothing has emerged as a standout method due to its ability to certify a provable lower bound on robustness radius under $\ell_p$-ball attacks. Recognizing its success, research in the time series domain has started focusing on these aspects. However, existing research predominantly focuses on time series forecasting, or under the non-$\ell_p$ robustness in statistic feature augmentation for time series classification~(TSC). Our review found that Randomized Smoothing performs modestly in TSC, struggling to provide effective assurances on datasets with poor robustness. Therefore, we propose a self-ensemble method to enhance the lower bound of the probability confidence of predicted labels by reducing the variance of classification margins, thereby certifying a larger radius. This approach also addresses the computational overhead issue of Deep Ensemble~(DE) while remaining competitive and, in some cases, outperforming it in terms of robustness. Both theoretical analysis and experimental results validate the effectiveness of our method, demonstrating superior performance in robustness testing compared to baseline approaches.
title Boosting Certified Robustness for Time Series Classification with Efficient Self-Ensemble
topic Machine Learning
Cryptography and Security
H.3.3
url https://arxiv.org/abs/2409.02802