提出新指标RR,揭示模型鲁棒性不能只靠准确率判断
Is it the model or the metric -- On robustness measures of deeplearning models
- 用鲁棒比(RR)衡量输入扰动下概率变化,补充传统鲁棒准确率
- 相同鲁棒准确率下,不同模型在不同扰动水平下表现差异显著
- 适合关注模型安全性的高风险场景研究者使用
深度学习模型的鲁棒性评估是自动化决策系统中的长期挑战。随着先进深度学习技术的发展,这类模型被广泛应用于医疗、教育、边境管控等高风险领域,因此理解其局限性并预测失效区域至关重要。本文聚焦于深度伪造检测任务,重新审视鲁棒性评估,提出鲁棒比(RR)作为补充指标,用于量化输入扰动下输出概率或归一化结果的变化。通过对比鲁棒准确率(RA)与鲁棒比(RR),发现尽管多个模型具有相似的鲁棒准确率,但在不同容忍度(扰动水平)下,其鲁棒比表现存在显著差异。
原文摘要 · Abstract (English)
Determining the robustness of deep learning models is an established and ongoing challenge within automated decision-making systems. With the advent and success of techniques that enable advanced deep learning (DL), these models are being used in widespread applications, including high-stake ones like healthcare, education, border-control. Therefore, it is critical to understand the limitations of these models and predict their regions of failures, in order to create the necessary guardrails for their successful and safe deployment. In this work, we revisit robustness, specifically investigating the sufficiency of robust accuracy (RA), within the context of deepfake detection. We present robust ratio (RR) as a complementary metric, that can quantify the changes to the normalized or probability outcomes under input perturbation. We present a comparison of RA and RR and demonstrate that despite similar RA between models, the models show varying RR under different tolerance (perturbation) levels.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。