আর্জেন্টিনা বনাম

আর্জেন্টিনা জাতীয় ফুটবল দল

A Discussion of ‘Adversarial Examples Are Not Bugs, They Are Features’: Adversarial Examples are Just Bugs, Too

A Discussion of ‘Adversarial Examples Are Not Bugs, They Are Features’: Adversarial Examples are Just Bugs, Too


We demonstrate that there exist adversarial examples which are just “bugs”:
aberrations in the classifier that are not intrinsic properties of the data distribution.
In particular, we give a new method for constructing adversarial examples which:

  1. Do not transfer between models, and
  2. Do not leak “non-robust features” which allow for learning, in the
    sense of Ilyas-Santurkar-Tsipras-Engstrom-Tran-Madry
    .

We replicate the Ilyas et al.
experiment of training on mislabeled adversarially-perturbed images
(Section 3.2 of ),
and show that it fails for our construction of adversarial perturbations.

The message is, whether adversarial examples are features or bugs depends
on how you find them — standard PGD finds features, but bugs are abundant as well.

We also give a toy example of a data distribution which has no “non-robust features”
(under any reasonable definition of feature), but for which standard training yields a highly non-robust
classifier.
This demonstrates, again, that adversarial examples can occur even if the data distribution does not
intrinsically have any vulnerable directions.

Background

Many have understood Ilyas et al.
to claim that adversarial examples are not “bugs”, but are “features”.
Specifically, Ilyas et al. postulate the following two worlds:
As communicated to us by the original authors.

  • World 1: Adversarial examples exploit directions irrelevant for classification (“bugs”).

    In this world, adversarial examples occur because classifiers behave
    poorly off-distribution,
    when they are evaluated on inputs that are not natural images.
    Here, adversarial examples would occur in arbitrary directions,
    having nothing to do with the true data distribution.
  • World 2: Adversarial examples exploit useful directions for classification (“features”).
    In this world, adversarial examples occur in directions that are still “on-distribution”,
    and which contain features of the target class.
    For example, consider the perturbation that
    makes an image of a dog to be classified as a cat.
    In World 2, this perturbation is not purely random, but has something to do with cats.
    Moreover, we expect that this perturbation transfers to other classifiers trained to distinguish cats
    vs. dogs.

Our main contribution is demonstrating that these worlds are not mutually exclusive — and in fact, we
are in both.
Ilyas et al.
show that there exist adversarial examples in World 2, and we show there exist
examples in World 1.

Constructing Non-transferrable Targeted Adversarial Examples


We propose a method to construct targeted adversarial examples for a given classifier
$f$,
which do not transfer to other classifiers trained for the same problem.

Recall that for a classifier $f$, an input example $(x, y)$, and target class $y_{targ}$,
a targeted adversarial example is an $x’$ such that $||x – x’||\leq \eps$ and
$f(x’) = y_{targ}$.

The standard method of constructing adversarial examples is via Projected Gradient Descent (PGD)

PGD is described in the appendix.

which starts at input $x$, and iteratively takes steps $\{x_t\}$
to minimize the loss $L(f, x_t, y_{targ})$.
That is, we take steps in the direction
$$-\nabla_x L(f, x_t, y_{targ})$$
where $L(f, x, y)$ is the loss of $f$ on input $x$, label $y$.

Note that since PGD steps in the gradient direction towards the target class,
we may expect these adversarial examples have feature leakage from the target class.
For example, suppose we are perturbing an image of a dog into a plane (which usually appears against a blue
background).
It is plausible that the gradient direction tends to make the dog image more blue,
since the “blue” direction is correlated with the plane class.
In our construction below, we attempt to eliminate such feature leakage.

A Discussion of ‘Adversarial Examples Are Not Bugs, They Are Features’: Adversarial Examples are Just Bugs, Too
An illustration of the image-manifold for adversarially perturbing a dog to a plane.
The gradient of the loss can be thought of as having an on-manifold “feature component”
and an off-manifold “random component”.
PGD steps along both components, hence causing feature-leakage in adversarial examples.
Our construction below attempts to step only in the off-manifold direction.

Our Construction

Let $\{f_i : \R^n \to \cY\}_i$ be an ensemble of classifiers
for the same classification problem as $f$.
For example, we can let $\{f_i\}$ be a collection of ResNet18s trained from
different random initializations.

For input example $(x, y)$ and target class $y_{targ}$,
we perform iterative updates to find adversarial attacks — as in PGD.
However, instead of stepping directly in the gradient direction, we
step in the direction

Formally, we replace the iterative step with
$$x_{t+1} \gets \Pi_\eps\left( x_t
– \alpha( \nabla_x L(f, x_t, y_{targ}) + \E_i[ \nabla_x L(f_i, x_t, y)]) \right)$$
where $\Pi_\eps$ is the projection onto the $\eps$-ball around $x$.

$$-\left( \nabla_x L(f, x_t, y_{targ}) + \E_i[ \nabla_x L(f_i, x_t, y)] \right)$$

That is, instead of taking gradient steps to minimize $L(f, x, y_{targ})$,
we minimize the “disentangled loss”

We could also consider explicitly using the ensemble to decorrelate,
by stepping in direction
$\nabla_x L(f, x, y_{targ}) – \E_i[ \nabla_x L(f_i, x, y_{targ})]$.
This works well for small $\epsilon$,
but the given loss has better optimization properties for larger $\epsilon$.

$$L(f, x, y_{targ}) + \E_i[L(f_i, x, y)]$$
This loss encourages finding an $x_t$ which is adversarial for $f$,
but not for the ensemble $\{f_i\}$.

These adversarial examples will not be adversarial for the ensemble $\{f_i\}$. But perhaps surprisingly,
these examples are also not adversarial for
new classifiers trained for the same problem.

Experiments

We train a ResNet18 on CIFAR10 as our target classifier $f$.
For our ensemble, we train 10 ResNet18s on CIFAR10, from fresh random initializations.
We then test the probability that
a targeted attack for $f$
transfers to a new (freshly-trained) ResNet18, with the same targeted class.
Our construction yields adversarial examples which do not transfer well to new models.

For $L_{\infty}$ attacks:

Attack Success Transfer Success
PGD 99.6% 52.1%
Ours 98.6% 0.8%

For $L_2$ attacks:

Attack Success Transfer Success
PGD 99.9% 82.5%
Ours 99.3% 1.7%

Adversarial Examples With No Features

Using the above, we can construct adversarial examples
which do not suffice for learning.
Here, we replicate the Ilyas et al. experiment
that “Non-robust features suffice for standard classification”
(Section 3.2 of ),
but show that it fails for our construction of adversarial examples.

To review, the Ilyas et al. non-robust experiment was:

  1. Train a standard classifier $f$ for CIFAR.
  2. From the CIFAR10 training set $S = \{(X_i, Y_i)\}$,
    construct an alternate train set $S’ = \{(X_i^{Y_i \to (Y_i + 1)}, Y_i + 1)\}$,
    where $X_i^{Y_i \to (Y_i +1)}$ denotes an adversarial example for
    $f$, perturbing $X_i$ from its true class $Y_i$ towards target class $Y_i+1 (\text{mod }10)$.
    Note that $S’$ appears to humans as “mislabeled examples”.
  3. Train a new classifier $f’$ on train set $S’$.
    Observe that this classifier has non-trivial accuracy on the original CIFAR distribution.

Ilyas et al. use Step (3) to argue that
adversarial examples have a meaningful “feature” component.

However, for adversarial examples constructed using our method, Step (3) fails.
In fact, $f’$ has good accuracy with respect to the “label-shifted” distribution
$(X, Y+1)$, which is intuitively what we trained on.

For $L_{\infty}$ attacks:

Test Acc on CIFAR: $(X, Y)$ Test Acc on Shifted-CIFAR: $(X, Y+1)$
PGD 23.7% 40.4%
Ours 2.5% 75.9%

Table: Test Accuracies of $f’$

For $L_2$ attacks:

Test Acc on CIFAR: $(X, Y)$ Test Acc on Shifted-CIFAR: $(X, Y+1)$
PGD 33.2% 27.3%
Ours 2.8% 70.8%

Table: Test Accuracies of $f’$

Adversarial Squares: Adversarial Examples from Robust Features

To further illustrate that adversarial examples can be “just bugs”,
we show that they can arise even when the true data distribution has no “non-robust features” — that is, no intrinsically vulnerable directions.

We are unaware of a satisfactory definition of “non-robust feature”, but we claim that for any
reasonable
intrinsic definition, this problem has no non-robust features.
Intrinsic here meaning, a definition which depends only on geometric properties of the data
distribution, and not on the family of classifiers, or the finite-sample training set.

We do not use the Ilyas et al. definition of “non-robust features,” because we believe it is vacuous.
In particular, by the Ilyas et al. definition, every distribution
has “non-robust features” — so the definition does not discern structural properties of the
distribution.
Moreover, for every “robust feature” $f$, there exists a corresponding “non-robust feature” $f’$, such
that $f$ and $f’$ agree on the data distribution — so the definition depends strongly on the
family of classifiers being considered.

In the following toy problem, adversarial vulnerability arises as a consequence of finite-sample
overfitting, and
label noise.

The problem is to distinguish between CIFAR-sized images that are either all-black or all-white,
with a small amount of random pixel noise and label noise.




A sample of images from the distribution.




Formally, let the distribution be as follows.
Pick label $Y \in \{\pm 1\}$ uniformly,
and let $$X :=
\begin{cases}
(+\vec{\mathbb{1}} + \vec\eta_\eps) \cdot \eta & \text{if $Y=1$}\\
(-\vec{\mathbb{1}} + \vec\eta_\eps) \cdot \eta & \text{if $Y=-1$}\\
\end{cases}$$

where $\vec\eta_\eps \sim [-0.1, +0.1]^d$ is uniform $L_\infty$ pixel noise,
and
$\eta \in \{\pm 1\} \sim Bernoulli(0.1)$ is the 10% label noise.

A plot of samples from a 2D-version of this distribution is shown to the right.

Notice that there exists a robust linear classifier for this problem which achieves perfect robust
classification, with up to $\eps = 0.9$ magnitude $L_\infty$ attacks.
However, if we sample 10000 training images from this distribution, and train
a ResNet18 to 99.9% train accuracy,

We optimize using Adam with learning-rate $0.00001$ and batch size $128$ for 20 epochs.

the resulting classifier is highly non-robust:
an $\eps=0.01$ perturbation suffices to flip the class of almost all test examples.

The input-noise and label noise are both essential for this construction.
One intuition for what is happening is: in the initial stage of training
the optimization learns the “correct” decision boundary (indeed, stopping after 1 epoch results in a robust
classifier).
However, optimizing for close to 0 train-error requires a network with high Lipshitz constant
to fit the label-noise, which hurts robustness.






Left: The training set (labels color-coded). Middle: The classifier after 10 SGD steps.
Right: The classifier at the end of training. Note that it is overfit, and not robust.

Figure adapted from .


Addendum: Data Poisoning via Adversarial Examples

As an addendum, we observe that the “non-robust features”
experiment of (Section 3.2)
directly implies data-poisoning attacks:
An adversary that is allowed to imperceptibly change every image in the training set can destroy the
accuracy of the learnt classifier — and can moreover apply an arbitrary permutation
to the classifier output labels (e.g. swapping cats and dogs).

To see this, recall that the original “non-robust features” experiment shows:Using our previous
notation, and also using vanilla PGD to find adversarial examples.

1. If we train on distribution $(X^{Y \to (Y+1)}, Y+ 1)$ the classifier learns to predict well
on distribution $(X, Y)$.

By permutation-symmetry of the labels, this implies that:

2. If we train on distribution $(X^{Y \to (Y+1)}, Y)$ the classifier learns to predict well
on distribution $(X, Y-1)$.

Note that in case (2), we are training with correct labels, just perturbing the inputs imperceptibly,
but the classifier learns to predict the cyclically-shifted labels.
Concretely, using the original numbers of
Table 1 in , this reduction implies that

an adversary can perturb the CIFAR10 train set by $\eps=0.5$ in $L_2$,
and cause the learnt classifier to output shifted-labels
43.7% of the time
(cats classified as birds, dogs as deers, etc).

This should extend to attacks that force arbitrary desired permutations of the labels.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

阿根廷对阵布基纳法索 阿根廷 - 布基纳法索 阿根廷对阵 阿根廷 阿根廷国家足球队 布基纳法索国家足球队 阿根廷国家足球队对阵布基纳法索国家足球队阵容 阿根廷比赛 哪里观看阿根廷国家足球队对阵布基纳法索国家足球队的比赛 阿根廷对阵布基纳法索 俄亥俄州立大学对阵爱荷华大学 爱荷华大学对阵俄亥俄州立大学 爱荷华大学橄榄球 杰里迈亚·史密斯 (Jeremiah Smith) 杰里迈亚·史密斯数据 爱荷华大学 俄亥俄州立大学 OSU对阵爱荷华大学 朱利安·萨因 (Julian Sayin) 爱荷华大学比赛 俄亥俄州立大学 爱荷华大学 俄亥俄州立大学七叶树队 (Buckeyes) 橄榄球 俄亥俄州立大学比分 爱荷华大学比分 俄亥俄州立大学七叶树队对阵爱荷华大学鹰眼队 (Hawkeyes) 比赛球员数据 俄亥俄州立大学七叶树队 七叶树队橄榄球 鹰眼队橄榄球 柯克·费伦茨 (Kirk Ferentz) 汉克·布朗 (Hank Brown) 俄亥俄州立大学橄榄球赛程 贾科比·杰克逊 (Ja'Kobi Jackson) 爱荷华大学鹰眼队 俄亥俄州立大学比赛在哪个频道播出 哪里观看俄亥俄州立大学七叶树队对阵爱荷华大学鹰眼队的橄榄球比赛 今天俄亥俄州立大学比赛在哪个频道播出 教士队 (Padres) 对阵酿酒人队 (Brewers) 酿酒人队 酿酒人队比赛 密尔沃基酿酒人队 酿酒人队对阵教士队 酿酒人队比分 教士队 教士队比赛 教士队今日比赛 酿酒人队今日比赛 圣地亚哥教士队 泰·弗朗斯 (Ty France) 曼尼·马查多 (Manny Machado) 威廉·孔特雷拉斯 (William Contreras) 密尔沃基 教士队 - 酿酒人队 教士队比分 特雷弗·梅吉尔 (Trevor Megill) 酿酒人队赛程 教士队 酿酒人队 梅吉尔 酿酒人队 酿酒人队比赛 酿酒人队 教士队 孔特雷拉斯 酿酒人队 教士队对阵密尔沃基酿酒人队 今日MLB比赛 Baseball Savant Lucki Lucki被刺伤 Lucki被刺伤了吗 说唱歌手Lucki Lucki遇刺事件 美国 - 墨西哥 墨西哥对阵美国 墨西哥国家队 美国对阵墨西哥 迭戈·坎皮略 (Diego Campillo) 墨西哥国家足球队 劳尔·兰赫尔 (Raúl Rangel) 友谊赛 路易斯·罗莫 (Luis Romo) 墨西哥何时比赛 墨西哥对阵美国 美国美国对墨西哥 墨西哥对阵 奥尔贝林·皮内达 迈阿密(佛罗里达州)对克莱姆森 迈阿密橄榄球 克莱姆森对迈阿密 迈阿密对克莱姆森 迈阿密飓风队 迈阿密飓风队橄榄球 达里安·门萨 迈阿密 迈阿密-克莱姆森 迈阿密大学橄榄球 克莱姆森-迈阿密 库珀·巴卡特 迈阿密对克莱姆森预测 麦克尼斯州立大学对LSU LSU对麦克尼斯 麦克尼斯橄榄球 LSU今日比赛 麦克尼斯 勇士队对道奇队 道奇队今日比赛 塔里克·斯库巴尔 道奇队赛程 勇士队今日比赛 斯库巴尔 亚特兰大勇士队对道奇队 扬基队对光芒队 德鲁·拉斯穆森 扬基队 扬基队今日比赛 坦帕湾光芒队 光芒队 扬基队比赛 纽约扬基队 扬基队今日比赛 光芒队比赛 扬基队比赛 光芒队今日比赛 NYY 扬基队-光芒队 奥斯汀·威尔斯 纽约扬基队 扬基队 阿肯色大学对德州农工大学 德州农工大学橄榄球 德州理工大学对科罗拉多大学 德州理工大学橄榄球 迪昂·桑德斯 科罗拉多大学橄榄球 德州理工大学 科罗拉多大学对德州理工大学 科罗拉多大学水牛队橄榄球 아르헨티나 대 부르키나파소 아르헨티나 - 부르키나파소 아르헨티나 대 아르헨티나 아르헨티나 축구 국가대표팀 부르키나파소 축구 국가대표팀 아르헨티나 대 부르키나파소 축구 국가대표팀 선발 명단 아르헨티나 경기 아르헨티나 대 부르키나파소 축구 국가대표팀 경기 중계 정보 아르헨티나 대 부르키나파소 오하이오 주립대 대 아이오와대 아이오와대 대 오하이오 주립대 아이오와대 미식축구 제레미아 스미스 제레미아 스미스 기록 아이오와대 오하이오 주립대 OSU 대 아이오와대 줄리안 세이인 아이오와대 경기 오하이오 주립대 아이오와대 오하이오 주립대 버키스 미식축구 오하이오 주립대 점수 아이오와대 점수 오하이오 주립대 버키스 대 아이오와대 호키스 미식축구 경기 선수 기록 오하이오 주립대 버키스 버키스 미식축구 호키스 미식축구 커크 페렌츠 행크 브라운 오하이오 주립대 미식축구 일정 자코비 잭슨 아이오와대 호키스 오하이오 주립대 경기 중계 채널 오하이오 주립대 버키스 대 아이오와대 호키스 미식축구 경기 시청 방법 오늘 오하이오 주립대 경기 중계 채널 파드리스 대 브루어스 브루어스 브루어스 경기 밀워키 브루어스 브루어스 대 파드리스 브루어스 점수 파드리스 파드리스 경기 오늘 파드리스 경기 오늘 브루어스 경기 샌디에이고 파드리스 타이 프랑스 매니 마차도 윌리엄 콘트레라스 밀워키 파드리스 - 브루어스 파드리스 점수 트레버 메길 브루어스 일정 파드리스 브루어스 메길 브루어스 브루어스 경기 브루어스 파드리스 콘트레라스 브루어스 파드리스 대 밀워키 브루어스 오늘 MLB 경기 베이스볼 사반트 럭키(Lucki) 럭키 피습 럭키가 칼에 찔렸나요? 래퍼 럭키 럭키 피습 사건 미국 - 멕시코 멕시코 대 미국 멕시코 국가대표팀 미국 대 멕시코 디에고 캄필로 멕시코 축구 국가대표팀 라울 랑헬 친선 경기 루이스 로모 멕시코 경기 일정 멕시코 대 미국 미국 미국 대 멕시코 멕시코 대 오르벨린 피네다 마이애미 대 클렘슨 마이애미 풋볼 클렘슨 대 마이애미 마이애미 대 클렘슨 마이애미 허리케인스 마이애미 허리케인스 풋볼 다리안 멘사 마이애미 마이애미 클렘슨 UM 풋볼 클렘슨 마이애미 쿠퍼 바케이트 마이애미 대 클렘슨 경기 예측 맥니스 주립대 대 LSU LSU 대 맥니스 맥니스 풋볼 오늘 LSU 경기 맥니스 브레이브스 대 다저스 오늘 다저스 경기 타릭 스쿠발 다저스 일정 오늘 브레이브스 경기 스쿠발 애틀랜타 브레이브스 대 다저스 양키스 대 레이스 드류 라스무센 양키스 오늘 양키스 경기 탬파베이 레이스 레이스 양키스 경기 뉴욕 양키스 오늘 양키스 경기 레이스 경기 양키스 경기 오늘 레이스 경기 NYY 양키스 레이스 오스틴 웰스 NY 양키스 양키 아칸소 대 텍사스 A&M A&M 풋볼 텍사스 공대 대 콜로라도 텍사스 공대 풋볼 디온 샌더스 CU 풋볼 텍사스 공대 콜로라도 대 텍사스 공대 CU 버프스 풋볼 アルゼンチン対ブルキナファソ アルゼンチン - ブルキナファソ アルゼンチン対 アルゼンチン アルゼンチン代表(サッカー) ブルキナファソ代表(サッカー) アルゼンチン代表対ブルキナファソ代表の出場メンバー アルゼンチンの試合 アルゼンチン代表対ブルキナファソ代表の視聴方法 アルゼンチン対ブルキナファソ オハイオ州立大対アイオワ大 アイオワ大対オハイオ州立大 アイオワ大フットボール ジェレマイア・スミス ジェレマイア・スミスの成績 アイオワ大・オハイオ州立大 OSU対アイオワ大 ジュリアン・サイン アイオワ大の試合 オハイオ州立大・アイオワ大 オハイオ州立大バッカイズ・フットボール オハイオ州立大のスコア アイオワ大のスコア オハイオ州立大バッカイズ対アイオワ大ホークアイズの試合・選手成績 オハイオ州立大バッカイズ バッカイズ・フットボール ホークアイズ・フットボール カーク・フェレンツ ハンク・ブラウン オハイオ州立大フットボールの日程 ジャコビ・ジャクソン アイオワ大ホークアイズ オハイオ州立大の試合の放送チャンネル オハイオ州立大バッカイズ対アイオワ大ホークアイズの視聴方法 今日のオハイオ州立大の試合の放送チャンネル パドレス対ブルワーズ ブルワーズ ブルワーズの試合 ミルウォーキー・ブルワーズ ブルワーズ対パドレス ブルワーズのスコア パドレス パドレスの試合 今日のパドレスの試合 今日のブルワーズの試合 サンディエゴ・パドレス タイ・フランス マニー・マチャド ウィリアム・コントレラス ミルウォーキー パドレス - ブルワーズ パドレスのスコア トレバー・メギル ブルワーズの日程 パドレス・ブルワーズ メギル・ブルワーズ ブルワーズの試合 ブルワーズ・パドレス コントレラス・ブルワーズ パドレス対ミルウォーキー・ブルワーズ 今日のMLBの試合 ベースボール・サバント Lucki Lucki 刺される Luckiは刺されたのか ラッパー Lucki Lucki 刺傷事件 アメリカ対メキシコ メキシコ対アメリカ メキシコ代表 アメリカ対メキシコ ディエゴ・カンピージョ メキシコ代表(サッカー) ラウル・ランヘル 親善試合 ルイス・ロモ メキシコの試合日程 メキシコ対USA アメリカ米国対メキシコ メキシコ対 オルベリン・ピネダ マイアミ対クレムソン マイアミ・フットボール クレムソン対マイアミ マイアミ対クレムソン マイアミ・ハリケーンズ マイアミ・ハリケーンズ・フットボール ダリアン・メンサ マイアミ マイアミ・クレムソン UMフットボール クレムソン・マイアミ クーパー・バーケイト マイアミ対クレムソン 予想 マクニース州立大対LSU LSU対マクニース マクニース・フットボール LSUの今日の試合 マクニース ブレーブス対ドジャース ドジャースの今日の試合 タリク・スクーバル ドジャースの日程 ブレーブスの今日の試合 スクーバル アトランタ・ブレーブス対ドジャース ヤンキース対レイズ ドリュー・ラスムッセン ヤンキース ヤンキースの今日の試合 タンパベイ・レイズ レイズ ヤンキースの試合 ニューヨーク・ヤンキース ヤンキースの今日の試合 レイズの試合 ヤンキースの試合 レイズの今日の試合 NYY