English

Adversarial Robustness via Fisher-Rao Regularization

Machine Learning 2022-06-15 v3 Computer Vision and Pattern Recognition

Abstract

Adversarial robustness has become a topic of growing interest in machine learning since it was observed that neural networks tend to be brittle. We propose an information-geometric formulation of adversarial defense and introduce FIRE, a new Fisher-Rao regularization for the categorical cross-entropy loss, which is based on the geodesic distance between the softmax outputs corresponding to natural and perturbed input features. Based on the information-geometric properties of the class of softmax distributions, we derive an explicit characterization of the Fisher-Rao Distance (FRD) for the binary and multiclass cases, and draw some interesting properties as well as connections with standard regularization metrics. Furthermore, for a simple linear and Gaussian model, we show that all Pareto-optimal points in the accuracy-robustness region can be reached by FIRE while other state-of-the-art methods fail. Empirically, we evaluate the performance of various classifiers trained with the proposed loss on standard datasets, showing up to a simultaneous 1\% of improvement in terms of clean and robust performances while reducing the training time by 20\% over the best-performing methods.

Keywords

Cite

@article{arxiv.2106.06685,
  title  = {Adversarial Robustness via Fisher-Rao Regularization},
  author = {Marine Picot and Francisco Messina and Malik Boudiaf and Fabrice Labeau and Ismail Ben Ayed and Pablo Piantanida},
  journal= {arXiv preprint arXiv:2106.06685},
  year   = {2022}
}

Comments

IEEE Transactions on Pattern Analysis and Machine Intelligence (Early Access)

R2 v1 2026-06-24T03:07:25.190Z