用后验一致性评估模型在分布偏移下的鲁棒性,比准确率更可靠。
Rethinking Robustness in Machine Learning: A Posterior Agreement Approach
- 基于后验一致性理论,提出新鲁棒性评估框架。
- 在对抗攻击和域泛化场景中均优于传统准确率指标。
- 无需标注数据,适合检测模型在不同偏移下的脆弱点。
算法在协变量偏移下的鲁棒性是实际部署中一个根本性问题。现有评估方法主要依赖标准泛化,以准确率等任务性能指标衡量鲁棒性,缺乏理论基础,亟需一种严谨的分布偏移下鲁棒性评估范式。本文设定鲁棒性度量的理想标准,提出一种基于后验一致性(Posterior Agreement, PA)理论的新型原则性评估框架,并将其扩展至协变量偏移场景。我们设计了一种鲁棒性评估度量,在受控环境和两类典型偏移场景(对抗学习与域泛化)中进行实证分析。通过在不同偏移性质、程度及受影响样本比例下测试多个模型,结果表明PA能可靠揭示学习算法的脆弱性,且判别能力高于基于准确率的度量,同时无需监督信号。
原文摘要 · Abstract (English)
The robustness of algorithms against covariate shifts is a fundamental problem with critical implications for the deployment of machine learning algorithms in the real world. Current evaluation methods predominantly measure robustness through the lens of standard generalization, relying on task performance measures like accuracy. This approach lacks a theoretical justification and underscores the need for a principled foundation of robustness assessment under distribution shifts. In this work, we set the desiderata for a robustness measure, and we propose a novel principled framework for the robustness assessment problem that directly follows the Posterior Agreement (PA) theory of model validation. Specifically, we extend the PA framework to the covariate shift setting and propose a measure for robustness evaluation. We assess the soundness of our measure in controlled environments and through an empirical robustness analysis in two different covariate shift scenarios: adversarial learning and domain generalization. We illustrate the suitability of PA by evaluating several models under different nature and magnitudes of shift, and proportion of affected observations. The results show that PA offers a reliable analysis of the vulnerabilities in learning algorithms across different shift conditions and provides higher discriminability than accuracy-based measures, while requiring no supervision.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。