Certifiably Robust Variational Autoencoders

被引:0
|
作者
Barrett, Ben [1 ]
Camuto, Alexander [1 ,3 ]
Willetts, Matthew [2 ,3 ]
Rainforth, Tom [1 ]
机构
[1] Univ Oxford, Oxford, England
[2] UCL, London, England
[3] Alan Turing Inst, London, England
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
We introduce an approach for training variational autoencoders (VAEs) that are certifiably robust to adversarial attack. Specifically, we first derive actionable bounds on the minimal size of an input perturbation required to change a VAE's reconstruction by more than an allowed amount, with these bounds depending on certain key parameters such as the Lipschitz constants of the encoder and decoder. We then show how these parameters can be controlled, thereby providing a mechanism to ensure a priori that a VAE will attain a desired level of robustness. Moreover, we extend this to a complete practical approach for training such VAEs to ensure our criteria are met. Critically, our method allows one to specify a desired level of robustness upfront and then train a VAE that is guaranteed to achieve this robustness. We further demonstrate that these Lipschitz-constrained VAEs are more robust to attack than standard VAEs in practice.
引用
收藏
页数:21
相关论文
共 50 条
  • [1] CARE: Certifiably Robust Learning with Reasoning via Variational Inference
    Zhang, Jiawei
    Li, Linyi
    Zhang, Ce
    Li, Bo
    2023 IEEE CONFERENCE ON SECURE AND TRUSTWORTHY MACHINE LEARNING, SATML, 2023, : 554 - 574
  • [2] CARE: Certifiably Robust Learning with Reasoning via Variational Inference
    Zhang, Jiawei
    Li, Linyi
    Zhang, Ce
    Li, Bo
    arXiv, 2022,
  • [3] Certifiably Robust Image Watermark
    Jiang, Zhengyuan
    Guo, Moyang
    Hui, Yuepeng
    Jia, Jinyuan
    Gong, Neil Zhenqiang
    COMPUTER VISION - ECCV 2024, PT LXXVII, 2024, 15135 : 427 - 443
  • [4] Robust Haze and Thin Cloud Removal via Conditional Variational Autoencoders
    Ding, Haidong
    Xie, Fengying
    Qiu, Linwei
    Zhang, Xiaozhe
    Shi, Zhenwei
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62 : 1 - 16
  • [5] Physics-Integrated Variational Autoencoders for Robust and Interpretable Generative Modeling
    Takeishi, Naoya
    Kalousis, Alexandros
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34
  • [6] Robust Variational Autoencoders and Normalizing Flows for Unsupervised Network Anomaly Detection
    Najari, Naji
    Berlemont, Samuel
    Lefebvre, Gregoire
    Duffner, Stefan
    Garcia, Christophe
    ADVANCED INFORMATION NETWORKING AND APPLICATIONS, AINA-2022, VOL 2, 2022, 450 : 281 - 292
  • [7] Towards Certifiably Robust Face Recognition
    Paik, Seunghun
    Kim, Dongsoo
    Hwang, Chanwoo
    Kim, Sunpill
    Seo, Jae Hong
    COMPUTER VISION - ECCV 2024, PT LXXXV, 2025, 15143 : 143 - 161
  • [8] Mixture variational autoencoders
    Jiang, Shuoran
    Chen, Yarui
    Yang, Jucheng
    Zhang, Chuanlei
    Zhao, Tingting
    PATTERN RECOGNITION LETTERS, 2019, 128 : 263 - 269
  • [9] An Introduction to Variational Autoencoders
    Kingma, Diederik P.
    Welling, Max
    FOUNDATIONS AND TRENDS IN MACHINE LEARNING, 2019, 12 (04): : 4 - 89
  • [10] Subitizing with Variational Autoencoders
    Wever, Rijnder
    Runia, Tom F. H.
    COMPUTER VISION - ECCV 2018 WORKSHOPS, PT III, 2019, 11131 : 617 - 627