Learning Fair Robustness via Domain Mixup

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Adversarial training is one of the predominant techniques for training classifiers that are robust to adversarial attacks. Recent work, however has found that adversarial training, which makes the overall classifier robust, it does not necessarily provide equal amount of robustness for all classes. In this paper, we propose the use of mixup for the problem of learning fair robust classifiers, which can provide similar robustness across all classes. Specifically, the idea is to mix inputs from the same classes and perform adversarial training on mixed up inputs. We present a theoretical analysis of this idea for the case of linear classifiers and show that mixup combined with adversarial training can provably reduce the class-wise robustness disparity. This method not only contributes to reducing the disparity in class-wise adversarial risk, but also the class-wise natural risk. Complementing our theoretical analysis, we also provide experimental results on both synthetic data and the real world dataset (CIFAR-10), which shows improvement in class wise disparities for both natural and adversarial risks.

Original languageEnglish (US)
Title of host publicationConference Record of the 58th Asilomar Conference on Signals, Systems and Computers, ACSSC 2024
EditorsMichael B. Matthews
PublisherIEEE Computer Society
Pages196-202
Number of pages7
ISBN (Electronic)9798350354058
DOIs
StatePublished - 2024
Event58th Asilomar Conference on Signals, Systems and Computers, ACSSC 2024 - Hybrid, Pacific Grove, United States
Duration: Oct 27 2024Oct 30 2024

Publication series

NameConference Record - Asilomar Conference on Signals, Systems and Computers
ISSN (Print)1058-6393

Conference

Conference58th Asilomar Conference on Signals, Systems and Computers, ACSSC 2024
Country/TerritoryUnited States
CityHybrid, Pacific Grove
Period10/27/2410/30/24

ASJC Scopus subject areas

  • Signal Processing
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Learning Fair Robustness via Domain Mixup'. Together they form a unique fingerprint.

Cite this