Confidential + Proprietary Confidential + Proprietary
Adversarial Examples are a Natural Consequence of Test Error in Noise
Nic Ford*, Justin Gilmer*, Nicholas Carlini, Dogus Cubuk
*equal contribution
Adversarial Examples are a Natural Consequence of Test Error in - - PowerPoint PPT Presentation
Adversarial Examples are a Natural Consequence of Test Error in Noise Nic Ford*, Justin Gilmer*, Nicholas Carlini, Dogus Cubuk *equal contribution Confidential + Proprietary Confidential + Proprietary Robust (out of distribution)
Confidential + Proprietary Confidential + Proprietary
*equal contribution
Confidential + Proprietary
Train on p(x) Test on q(x)
Confidential + Proprietary
Confidential + Proprietary
[Hendrycks et. al] https://arxiv.org/pdf/1807.01697.pdf
robustness to distributional shift.
See also: [Mu, Gilmer] "MNIST-C" https://arxiv.org/abs/1906.02337 [Pei et. al.] - https://arxiv.org/pdf/1712.01785.pdf
Proprietary + Confidential
x x_adv
[Goodfellow et. al.]
Confidential + Proprietary
Confidential + Proprietary
Confidential + Proprietary
Confidential + Proprietary
Confidential + Proprietary
Confidential + Proprietary
Confidential + Proprietary
Test error > 0 (iid, ood) -> errors exist -> there is a nearest error
Confidential + Proprietary
See also Fawzi et. al.
Confidential + Proprietary
Confidential + Proprietary
Confidential + Proprietary
nearest error.
given measured o.o.d robustness.
than tiny perturbations.
robustness, is it more secure?