Works: an Extreme Value Theory Approach
نویسندگان
چکیده
The robustness of neural networks to adversarial examples has received great attention due to security implications. Despite various attack approaches to crafting visually imperceptible adversarial examples, little has been developed towards a comprehensive measure of robustness. In this paper, we provide a theoretical justification for converting robustness analysis into a local Lipschitz constant estimation problem, and propose to use the Extreme Value Theory for efficient evaluation. Our analysis yields a novel robustness metric called CLEVER, which is short for Cross Lipschitz Extreme Value for nEtwork Robustness. The proposed CLEVER score is attack-agnostic and computationally feasible for large neural networks. Experimental results on various networks, including ResNet, Inceptionv3 and MobileNet, show that (i) CLEVER is aligned with the robustness indication measured by the `2 and `∞ norms of adversarial examples from powerful attacks, and (ii) defended networks using defensive distillation or bounded ReLU indeed achieve better CLEVER scores. To the best of our knowledge, CLEVER is the first attack-independent robustness metric that can be applied to any neural network classifier.
منابع مشابه
Numerical convergence of the block-maxima approach to the Generalized Extreme Value distribution
In this paper we perform an analytical and numerical study of Extreme Value distributions in discrete dynamical systems. In this setting, recent works have shown how to get a statistics of extremes in agreement with the classical Extreme Value Theory. We pursue these investigations by giving analytical expressions of Extreme Value
متن کاملPlace of Prophet Jonah in the collection of Mahmoud Farshchian's works With Joseph Campbell's "Monomyth" theory approach
Abstract The term "myth" today has a variety of histories, theories and critiques, and has been addressed from various perspectives. "Myth" is a word that is derived from the Latin word historiography (historia), the knowledge gained by the research. The word itself is derived from the Greek historical "histor" meaning "wise man". In general, you can count on myths from three perspectives. ...
متن کاملThe Effectiveness of Life Style Education with the Choice Theory Approach to Increasing the Quality of Life of Women with Extreme Binge Eating Disorder.
Introduction: Binge eating disorder is associated with many problems, including physical and psychological problems. Reducing the quality of life is one of the components that include the dimensions of health, physical, mental health, social relations and environmental health, which is reduced by extreme overeating. Therefore, the present study aimed to investigate The effectiveness of life...
متن کاملInvestigating Effect of Oil Revenues on Social Capital in Oil Rentier Countries: An Extreme Bounds Analysis Approach (EBA)
The volatility of oil revenues in rentier countries, due to the large share of oil revenue in their economies, affects many variables. Oil revenues can also affect social behavior and culture. Therefore, social capital, as the result of social networks and institutions, can be directly and indirectly affected by oil rents. The review of economic literature suggests that oil revenues could poten...
متن کاملA Hybrid Machine Learning Method for Intrusion Detection
Data security is an important area of concern for every computer system owner. An intrusion detection system is a device or software application that monitors a network or systems for malicious activity or policy violations. Already various techniques of artificial intelligence have been used for intrusion detection. The main challenge in this area is the running speed of the available implemen...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2018