The fragility of modern machine learning models has drawn a considerable amount of attention from both academia and the public. While immense interests were in either crafting adversarial attacks as a way to measure the robustness of neural networks or devising worst-case analytical robustness verification with guarantees, few methods could enjoy both scalability and robustness guarantees at the same time. As an alternative to these attempts, randomized smoothing adopts a different prediction rule that enables statistical robustness arguments which easily scale to large networks. However, in this paper, we point out the side effects of current randomized smoothing workflows. Specifically, we articulate and prove two major points: 1) the decision boundaries of smoothed classifiers will shrink, resulting in disparity in class-wise accuracy; 2) applying noise augmentation in the training process does not necessarily resolve the shrinking issue due to the inconsistent learning objectives.
机构:
Max Planck Inst Res Collect Goods, Kurt Schumacher Str 10, D-53121 Bonn, GermanyMax Planck Inst Res Collect Goods, Kurt Schumacher Str 10, D-53121 Bonn, Germany
Engel, Christoph
JOURNAL OF INSTITUTIONAL AND THEORETICAL ECONOMICS-ZEITSCHRIFT FUR DIE GESAMTE STAATSWISSENSCHAFT,
2017,
173
(01):
: 106
-
109
机构:
Royal Childrens Hosp, Dept Gen Med, Infect Dis Unit, Melbourne, Vic, AustraliaRoyal Childrens Hosp, Dept Gen Med, Infect Dis Unit, Melbourne, Vic, Australia
Nairn, Elizabeth K.
论文数: 引用数:
h-index:
机构:
Wolf, Joshua
Buttery, Jim P.
论文数: 0引用数: 0
h-index: 0
机构:
Royal Childrens Hosp, Dept Gen Med, Infect Dis Unit, Melbourne, Vic, Australia
Univ Melbourne, Dept Paediat, Melbourne, Vic, Australia
Murdoch Childrens Res Inst, Melbourne, Vic, AustraliaRoyal Childrens Hosp, Dept Gen Med, Infect Dis Unit, Melbourne, Vic, Australia
机构:
Univ Vermont, Coll Med, Fletcher Allen Hlth Care, Burlington, VT 05405 USAUniv Vermont, Coll Med, Fletcher Allen Hlth Care, Burlington, VT 05405 USA
Tsai, Mitchell
Polk, James D.
论文数: 0引用数: 0
h-index: 0
机构:
NASA, Lyndon B Johnson Space Ctr, Space Med Div, Houston, TX 77058 USAUniv Vermont, Coll Med, Fletcher Allen Hlth Care, Burlington, VT 05405 USA
Polk, James D.
ANESTHESIA AND ANALGESIA,
2011,
113
(02):
: 431
-
431
机构:
CUNY, Ctr Nonprofit Strategy & Management, Austin W Marxe Sch Publ & Int Affairs, Baruch Coll, New York, NY 10010 USACUNY, Ctr Nonprofit Strategy & Management, Austin W Marxe Sch Publ & Int Affairs, Baruch Coll, New York, NY 10010 USA
Mitchell, George E.
Calabrese, Thad D.
论文数: 0引用数: 0
h-index: 0
机构:
NYU, Robert F Wagner Grad Sch Publ Serv, New York, NY USACUNY, Ctr Nonprofit Strategy & Management, Austin W Marxe Sch Publ & Int Affairs, Baruch Coll, New York, NY 10010 USA