arXiv (Cornell University) · 2018 · 157 citations · 21 references
Artificial IntelligenceConvolutional Neural NetworkEngineeringMachine LearningNovel RobustnessNetwork RobustnessAi SafetyRobust StatisticUncertainty QuantificationAdversarial Machine LearningExtreme Value TheoryRobust OptimizationRobustness IndicationExtreme Learning MachineComputer EngineeringComputer ScienceNeural NetworksDeep LearningExtreme StatisticGenerative Adversarial Network
Robustness of neural networks to adversarial examples is crucial for security, yet comprehensive measures are lacking. The study aims to justify converting robustness analysis into a local Lipschitz constant estimation problem and to propose using Extreme Value Theory for efficient evaluation. We develop CLEVER, an attack‑agnostic metric derived from Extreme Value Theory that estimates local Lipschitz constants and is computationally feasible for large networks. Experiments on ResNet, Inception‑v3, and MobileNet show that CLEVER aligns with ℓ2 and ℓ∞ robustness measures and that defended networks achieve higher CLEVER scores, making it the first attack‑independent metric applicable to any classifier.
The robustness of neural networks to adversarial examples has received great attention due to security implications. Despite various attack approaches to crafting visually imperceptible adversarial examples, little has been developed towards a comprehensive measure of robustness. In this paper, we provide a theoretical justification for converting robustness analysis into a local Lipschitz constant estimation problem, and propose to use the Extreme Value Theory for efficient evaluation. Our analysis yields a novel robustness metric called CLEVER, which is short for Cross Lipschitz Extreme Value for nEtwork Robustness. The proposed CLEVER score is attack-agnostic and computationally feasible for large neural networks. Experimental results on various networks, including ResNet, Inception-v3 and MobileNet, show that (i) CLEVER is aligned with the robustness indication measured by the $\ell_2$ and $\ell_\infty$ norms of adversarial examples from powerful attacks, and (ii) defended networks using defensive distillation or bounded ReLU indeed achieve better CLEVER scores. To the best of our knowledge, CLEVER is the first attack-independent robustness metric that can be applied to any neural network classifier.
21
Deep Residual Learning for Image Recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren et al. · 2016 · 214.9K citations · Full text
Image Classification, Deep Neural Networks, Machine Vision +14
Kishore Papineni, Salim Roukos, Todd J. Ward et al. · 2001 · 20.9K citations · Full text
Natural Language Processing, Computer-assisted Translation, Engineering +10
Distilling the Knowledge in a Neural Network
Geoffrey E. Hinton, Oriol Vinyals · arXiv (Cornell University) · 2015 · 13.9K citations · Full text