Robustness of classifiers_from_adversarial_to_random_noise

43
Robustness of classifiers: from adversarial to random noise hskksk @ 2017/2/3 1

Transcript of Robustness of classifiers_from_adversarial_to_random_noise

Page 1: Robustness of classifiers_from_adversarial_to_random_noise

Robustness of classifiers: from adversarial to random noise

hskksk @ 2017/2/3

1

Page 2: Robustness of classifiers_from_adversarial_to_random_noise

• nota&on

• /

2

Page 3: Robustness of classifiers_from_adversarial_to_random_noise

3

Page 4: Robustness of classifiers_from_adversarial_to_random_noise

Fawzi, A., Moosavi-Dezfooli, S.-M., & Frossard, P. (2016). Robustness of classifiers: from adversarial to random noise. In NIPS (pp. 1624–1632).

4

Page 5: Robustness of classifiers_from_adversarial_to_random_noise

• Deep learning state-of-the-art

• Adversarial ( )

• Adversarial

5

Page 6: Robustness of classifiers_from_adversarial_to_random_noise

Adversarial (1)

• :

6

Page 7: Robustness of classifiers_from_adversarial_to_random_noise

Adversarial (2)

worst-case

• worst-case

7

Page 9: Robustness of classifiers_from_adversarial_to_random_noise

(2)

• [18] empirical adversarial example

pixel

• [3] random adversarial

9

Page 10: Robustness of classifiers_from_adversarial_to_random_noise

• semi-random

• semi-random random/worst-case

• worst-case semi-random

10

Page 11: Robustness of classifiers_from_adversarial_to_random_noise

nota%on

11

Page 12: Robustness of classifiers_from_adversarial_to_random_noise

nota%on

クラス分類器

データ点

推定されたラベル

次元 の の任意の部分空間

12

Page 13: Robustness of classifiers_from_adversarial_to_random_noise

13

Page 14: Robustness of classifiers_from_adversarial_to_random_noise

adversarial

• adversarial

→ adversarial

14

Page 15: Robustness of classifiers_from_adversarial_to_random_noise

15

Page 16: Robustness of classifiers_from_adversarial_to_random_noise

16

Page 17: Robustness of classifiers_from_adversarial_to_random_noise

17

Page 18: Robustness of classifiers_from_adversarial_to_random_noise

1:

18

Page 19: Robustness of classifiers_from_adversarial_to_random_noise

• 1

19

Page 20: Robustness of classifiers_from_adversarial_to_random_noise

(d )

• e.g.

(

)

20

Page 21: Robustness of classifiers_from_adversarial_to_random_noise

(m=1 )

21

Page 22: Robustness of classifiers_from_adversarial_to_random_noise

1

• m

22

Page 23: Robustness of classifiers_from_adversarial_to_random_noise

23

Page 24: Robustness of classifiers_from_adversarial_to_random_noise

• pairwise

24

Page 25: Robustness of classifiers_from_adversarial_to_random_noise

( )

25

Page 26: Robustness of classifiers_from_adversarial_to_random_noise

(1)

• bound

• i j

worst-case

26

Page 27: Robustness of classifiers_from_adversarial_to_random_noise

(2)

• worst-case radius:

• :

27

Page 28: Robustness of classifiers_from_adversarial_to_random_noise

2: ( )

28

Page 29: Robustness of classifiers_from_adversarial_to_random_noise

• affine classifier

29

Page 30: Robustness of classifiers_from_adversarial_to_random_noise

( )

30

Page 31: Robustness of classifiers_from_adversarial_to_random_noise

2-1: (1)

• (5)

31

Page 32: Robustness of classifiers_from_adversarial_to_random_noise

2-1: (2)

• global 2

• 2

( )

32

Page 33: Robustness of classifiers_from_adversarial_to_random_noise

33

Page 34: Robustness of classifiers_from_adversarial_to_random_noise

1: 2-1 (1)

• 1 1

34

Page 35: Robustness of classifiers_from_adversarial_to_random_noise

1: 2-1 (2)

• [13]

• 1000

35

Page 36: Robustness of classifiers_from_adversarial_to_random_noise

1 (1)

• 1 2-1

36

Page 37: Robustness of classifiers_from_adversarial_to_random_noise

1 (2)

37

Page 38: Robustness of classifiers_from_adversarial_to_random_noise

2: (5)

38

Page 39: Robustness of classifiers_from_adversarial_to_random_noise

2 (1)

39

Page 40: Robustness of classifiers_from_adversarial_to_random_noise

2 (2)

• (5)

(5)

40

Page 41: Robustness of classifiers_from_adversarial_to_random_noise

3:

• NIPS,SPAIN,2016

41

Page 42: Robustness of classifiers_from_adversarial_to_random_noise

3

Po$lower → Pineapple

42

Page 43: Robustness of classifiers_from_adversarial_to_random_noise

• → adversarial

robust

• state-of-the-art semi-random

43