SOTAVerified

Towards Understanding the Robustness Against Evasion Attack on Categorical Data

2021-09-29ICLR 2022Unverified0· sign in to hype

Hongyan Bao, Yufei Han, Yujun Zhou, Yun Shen, Xiangliang Zhang

Unverified — Be the first to reproduce this paper.

Reproduce

Abstract

Characterizing and assessing the adversarial vulnerability of classification models with categorical input has been a practically important, while rarely explored research problem. Our work echoes the challenge by first unveiling the impact factors of adversarial vulnerability of classification models with categorical data based on an information-theoretic adversarial risk analysis about the targeted classifier. Though certifying the robustness of such classification models is intrinsically an NP-hard combinatorial problem, our study shows that the robustness certification can be solved via an efficient greedy exploration of the discrete attack space for any measurable classifiers with a mild smoothness constraint. Our proposed robustness certification framework is instantiated with deep neural network models applied on real-world safety-critic data sources. Our empirical observations confirm the impact of the key adversarial risk factors with categorical input.

Tasks

Reproductions