We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

stat.ML

Change to browse by:

References & Citations

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Statistics > Machine Learning

Title: Certifying Some Distributional Robustness with Principled Adversarial Training

Abstract: Neural networks are vulnerable to adversarial examples and researchers have proposed many heuristic attack and defense mechanisms. We address this problem through the principled lens of distributionally robust optimization, which guarantees performance under adversarial input perturbations. By considering a Lagrangian penalty formulation of perturbing the underlying data distribution in a Wasserstein ball, we provide a training procedure that augments model parameter updates with worst-case perturbations of training data. For smooth losses, our procedure provably achieves moderate levels of robustness with little computational or statistical cost relative to empirical risk minimization. Furthermore, our statistical guarantees allow us to efficiently certify robustness for the population loss. For imperceptible perturbations, our method matches or outperforms heuristic approaches.
Comments: ICLR 2018: this https URL
Subjects: Machine Learning (stat.ML); Machine Learning (cs.LG)
Cite as: arXiv:1710.10571 [stat.ML]
  (or arXiv:1710.10571v5 [stat.ML] for this version)

Submission history

From: Aman Sinha [view email]
[v1] Sun, 29 Oct 2017 07:27:57 GMT (1923kb)
[v2] Thu, 30 Nov 2017 18:01:49 GMT (1930kb)
[v3] Tue, 9 Jan 2018 20:20:25 GMT (2428kb)
[v4] Tue, 1 May 2018 05:52:13 GMT (2488kb)
[v5] Fri, 1 May 2020 07:29:34 GMT (2499kb)

Link back to: arXiv, form interface, contact.