The University of Southampton
University of Southampton Institutional Repository

Comparing complexities of decision boundaries for robust training: a universal approach

Comparing complexities of decision boundaries for robust training: a universal approach
Comparing complexities of decision boundaries for robust training: a universal approach

We investigate the geometric complexity of decision boundaries for robust training compared to standard training. By considering the local geometry of nearest neighbour sets, we study them in a model-agnostic way and theoretically derive a lower-bound R∈ R on the perturbation magnitude δ∈ R for which robust training provably requires a geometrically more complex decision boundary than accurate training. We show that state-of-the-art robust models learn more complex decision boundaries than their non-robust counterparts, confirming previous hypotheses. Then, we compute R for common image benchmarks and find that it also empirically serves as an upper bound over which label noise is introduced. We demonstrate for deep neural network classifiers that perturbation magnitudes δ≥ R lead to reduced robustness and generalization performance. Therefore, R bounds the maximum feasible perturbation magnitude for norm-bounded robust training and data augmentation. Finally, we show that R< 0.5 R for common benchmarks, where R is a distribution’s minimum nearest neighbour distance. Thus, we improve previous work on determining a distribution’s maximum robust radius.

0302-9743
627-645
Springer Cham
Kienitz, Daniel
3023b299-5ac1-47ee-9869-84f7aef7175d
Komendantskaya, Ekaterina
f12d9c23-5589-40b8-bcf9-a04fe9dedf61
Lones, Michael
12925c9c-11ed-44ef-b470-828d638d9fb4
Wang, Lei
Gall, Juergen
Chin, Tat-Jun
Sato, Imari
Chellappa, Rama
Kienitz, Daniel
3023b299-5ac1-47ee-9869-84f7aef7175d
Komendantskaya, Ekaterina
f12d9c23-5589-40b8-bcf9-a04fe9dedf61
Lones, Michael
12925c9c-11ed-44ef-b470-828d638d9fb4
Wang, Lei
Gall, Juergen
Chin, Tat-Jun
Sato, Imari
Chellappa, Rama

Kienitz, Daniel, Komendantskaya, Ekaterina and Lones, Michael (2023) Comparing complexities of decision boundaries for robust training: a universal approach. Wang, Lei, Gall, Juergen, Chin, Tat-Jun, Sato, Imari and Chellappa, Rama (eds.) In Computer Vision – ACCV 2022 - 16th Asian Conference on Computer Vision, Proceedings. vol. 13846 LNCS, Springer Cham. pp. 627-645 . (doi:10.1007/978-3-031-26351-4_38).

Record type: Conference or Workshop Item (Paper)

Abstract

We investigate the geometric complexity of decision boundaries for robust training compared to standard training. By considering the local geometry of nearest neighbour sets, we study them in a model-agnostic way and theoretically derive a lower-bound R∈ R on the perturbation magnitude δ∈ R for which robust training provably requires a geometrically more complex decision boundary than accurate training. We show that state-of-the-art robust models learn more complex decision boundaries than their non-robust counterparts, confirming previous hypotheses. Then, we compute R for common image benchmarks and find that it also empirically serves as an upper bound over which label noise is introduced. We demonstrate for deep neural network classifiers that perturbation magnitudes δ≥ R lead to reduced robustness and generalization performance. Therefore, R bounds the maximum feasible perturbation magnitude for norm-bounded robust training and data augmentation. Finally, we show that R< 0.5 R for common benchmarks, where R is a distribution’s minimum nearest neighbour distance. Thus, we improve previous work on determining a distribution’s maximum robust radius.

This record has no associated files available for download.

More information

Published date: 26 February 2023
Additional Information: Funding Information: Acknowledgements. D. Kienitz and E. Komendantskaya acknowledge support of EPSRC grant EP/T026952/1: AI Secure and Explainable by Construction (AISEC). Publisher Copyright: © 2023, The Author(s), under exclusive license to Springer Nature Switzerland AG.
Venue - Dates: 16th Asian Conference on Computer Vision, ACCV 2022, , Macao, China, 2022-12-04 - 2022-12-08

Identifiers

Local EPrints ID: 482740
URI: http://eprints.soton.ac.uk/id/eprint/482740
ISSN: 0302-9743
PURE UUID: 8798239a-4cc6-4e9b-90f5-f7c4783bf167

Catalogue record

Date deposited: 12 Oct 2023 16:38
Last modified: 17 Mar 2024 13:32

Export record

Altmetrics

Contributors

Author: Daniel Kienitz
Author: Ekaterina Komendantskaya
Author: Michael Lones
Editor: Lei Wang
Editor: Juergen Gall
Editor: Tat-Jun Chin
Editor: Imari Sato
Editor: Rama Chellappa

Download statistics

Downloads from ePrints over the past year. Other digital versions may also be available to download e.g. from the publisher's website.

View more statistics

Atom RSS 1.0 RSS 2.0

Contact ePrints Soton: eprints@soton.ac.uk

ePrints Soton supports OAI 2.0 with a base URL of http://eprints.soton.ac.uk/cgi/oai2

This repository has been built using EPrints software, developed at the University of Southampton, but available to everyone to use.

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we will assume that you are happy to receive cookies on the University of Southampton website.

×