2017

Exploring the Landscape of Spatial Robustness

Engstrom, Logan, Tran, Brandon, Tsipras, Dimitris et al.

Understand

The study of adversarial robustness has so far largely focused on perturbations bound in p-norms.

  • However, state-of-the-art models turn out to be also vulnerable to other, more natural classes of perturbations such as translations and rotations.
  • In this work, we thoroughly investigate the vulnerability of neural network--based classifiers to rotations and translations.
  • While data augmentation offers relatively small robustness, we use ideas from robust optimization and test-time input aggregation to significantly improve robustness.

Reading the bibliography…