English
 
Help Privacy Policy Disclaimer
  Advanced SearchBrowse

Item

ITEM ACTIONSEXPORT
  Disentangling Adversarial Robustness and Generalization

Stutz, D., Hein, M., & Schiele, B. (2018). Disentangling Adversarial Robustness and Generalization. Retrieved from http://arxiv.org/abs/1812.00740.

Item is

Files

show Files
hide Files
:
arXiv:1812.00740.pdf (Preprint), 3MB
 
File Permalink:
-
Name:
arXiv:1812.00740.pdf
Description:
File downloaded from arXiv at 2018-12-07 15:08
OA-Status:
Visibility:
Private
MIME-Type / Checksum:
application/pdf
Technical Metadata:
Copyright Date:
-
Copyright Info:
-

Locators

show

Creators

show
hide
 Creators:
Stutz, David1, Author           
Hein,, Matthias2, Author
Schiele, Bernt1, Author           
Affiliations:
1Computer Vision and Multimodal Computing, MPI for Informatics, Max Planck Society, ou_1116547              
2External Organizations, ou_persistent22              

Content

show
hide
Free keywords: Computer Science, Computer Vision and Pattern Recognition, cs.CV,Computer Science, Cryptography and Security, cs.CR,Computer Science, Learning, cs.LG,Statistics, Machine Learning, stat.ML
 Abstract: Obtaining deep networks that are robust against adversarial examples and
generalize well is an open problem. A recent hypothesis even states that both
robust and accurate models are impossible, i.e., adversarial robustness and
generalization are conflicting goals. In an effort to clarify the relationship
between robustness and generalization, we assume an underlying, low-dimensional
data manifold and show that: 1. regular adversarial examples leave the
manifold; 2. adversarial examples constrained to the manifold, i.e.,
on-manifold adversarial examples, exist; 3. on-manifold adversarial examples
are generalization errors, and on-manifold adversarial training boosts
generalization; 4. and regular robustness is independent of generalization.
These assumptions imply that both robust and accurate models are possible.
However, different models (architectures, training strategies etc.) can exhibit
different robustness and generalization characteristics. To confirm our claims,
we present extensive experiments on synthetic data (with access to the true
manifold) as well as on EMNIST, Fashion-MNIST and CelebA.

Details

show
hide
Language(s): eng - English
 Dates: 2018-12-032018
 Publication Status: Published online
 Pages: 20 p.
 Publishing info: -
 Table of Contents: -
 Rev. Type: -
 Identifiers: arXiv: 1812.00740
URI: http://arxiv.org/abs/1812.00740
BibTex Citekey: Stutz2018ARXIV
 Degree: -

Event

show

Legal Case

show

Project information

show

Source

show