English

Empirically Measuring Concentration: Fundamental Limits on Intrinsic Robustness

Machine Learning 2019-10-29 v2 Cryptography and Security Information Theory math.IT Machine Learning

Abstract

Many recent works have shown that adversarial examples that fool classifiers can be found by minimally perturbing a normal input. Recent theoretical results, starting with Gilmer et al. (2018b), show that if the inputs are drawn from a concentrated metric probability space, then adversarial examples with small perturbation are inevitable. A concentrated space has the property that any subset with Ω(1)\Omega(1) (e.g., 1/100) measure, according to the imposed distribution, has small distance to almost all (e.g., 99/100) of the points in the space. It is not clear, however, whether these theoretical results apply to actual distributions such as images. This paper presents a method for empirically measuring and bounding the concentration of a concrete dataset which is proven to converge to the actual concentration. We use it to empirically estimate the intrinsic robustness to \ell_\infty and 2\ell_2 perturbations of several image classification benchmarks. Code for our experiments is available at https://github.com/xiaozhanguva/Measure-Concentration.

Keywords

Cite

@article{arxiv.1905.12202,
  title  = {Empirically Measuring Concentration: Fundamental Limits on Intrinsic Robustness},
  author = {Saeed Mahloujifar and Xiao Zhang and Mohammad Mahmoody and David Evans},
  journal= {arXiv preprint arXiv:1905.12202},
  year   = {2019}
}

Comments

17 pages, 3 figures, 5 tables; NeurIPS final version

R2 v1 2026-06-23T09:30:42.716Z