arXiv:2501.12522cs.LG2025-01ICML被引 3

用拓扑方法发现模型对陌生数据处理能力弱

Topology of Out-of-Distribution Examples in Deep Neural Networks

  • 通过分析网络隐层特征的拓扑结构识别异常输入
  • 陌生数据的拓扑特征持续时间比正常数据长得多
  • 适合关注模型鲁棒性与安全性的研究人员

随着深度神经网络(DNN)广泛应用,其在面对陌生输入时的鲁棒性问题日益突出。现有模型在遭遇分布外(OOD)样本时往往过度自信且错误。本文提出一种基于隐层嵌入的拓扑分析方法,旨在识别指示OOD的拓扑特征——称为‘地标’。我们在基准数据集和真实大模型上进行了大量实验,发现训练良好的DNN会对训练数据产生拓扑简化,这一性质在真实大规模数据上依然成立,但对OOD样本不成立。具体而言,OOD样本的平均寿命(或持久性)显著长于训练或测试样本,表明DNN难以对陌生输入实现拓扑简化。该结果为真实DNN中的拓扑简化提供了新证据,并为基于拓扑信息的OOD检测策略奠定基础。

原文摘要 · Abstract (English)

As deep neural networks (DNNs) become increasingly common, concerns about their robustness do as well. A longstanding problem for deployed DNNs is their behavior in the face of unfamiliar inputs; specifically, these models tend to be overconfident and incorrect when encountering out-of-distribution (OOD) examples. In this work, we present a topological approach to characterizing OOD examples using latent layer embeddings from DNNs. Our goal is to identify topological features, referred to as landmarks, that indicate OOD examples. We conduct extensive experiments on benchmark datasets and a realistic DNN model, revealing a key insight for OOD detection. Well-trained DNNs have been shown to induce a topological simplification on training data for simple models and datasets; we show that this property holds for realistic, large-scale test and training data, but does not hold for OOD examples. More specifically, we find that the average lifetime (or persistence) of OOD examples is statistically longer than that of training or test examples. This indicates that DNNs struggle to induce topological simplification on unfamiliar inputs. Our empirical results provide novel evidence of topological simplification in realistic DNNs and lay the groundwork for topologically-informed OOD detection strategies.

OOD检测拓扑分析模型鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。