2020

Precise Statistical Analysis of Classification Accuracies for Adversarial Training

Javanmard, Adel, Soltanolkotabi, Mahdi

Understand

Despite the wide empirical success of modern machine learning algorithms and models in a multitude of applications, they are known to be highly susceptible to seemingly small indiscernible perturbations to the input data known as \emph{adversarial attacks}.

  • A variety of recent adversarial training procedures have been proposed to remedy this issue.
  • Despite the success of such procedures at increasing accuracy on adversarially perturbed inputs or \emph{robust accuracy}, these techniques often reduce accuracy on natural unperturbed inputs or \emph{standard accuracy}.
  • Complicating matters further, the effect and trend of adversarial training procedures on standard and robust accuracy is rather counter intuitive and radically dependent on a variety of factors including the perceived form of the perturbation during training, size/quality of data, model overparameterization, etc.

Reading the bibliography…