← Search

Alhussein Fawzi

12 accepted papers

2019

Adversarial Robustness through Local Linearization

NeurIPS 2019poster

Adversarial training is an effective methodology for training deep neural networks that are robust against adversarial, norm-bounded perturbations. However, the computational cost of adversarial training grows prohibitively as the size of the model and number of input dimensions increase. Further, t…

Cited by 367SourcePDFScholar
2019

Are Labels Required for Improving Adversarial Robustness?

NeurIPS 2019poster

Recent work has uncovered the interesting (and somewhat surprising) finding that training models to be invariant to adversarial perturbations requires substantially larger datasets than those required for standard classification. This result is a key hurdle in the deployment of robust machine learni…

2019

Robustness via Curvature Regularization, and Vice Versa

CVPR 2019poster

State-of-the-art classifiers have been shown to be largely vulnerable to adversarial perturbations. One of the most effective strategies to improve robustness is adversarial training. In this paper, we investigate the effect of adversarial training on the geometry of the classification landscape and…

Cited by 391PDFScholar
2018

Empirical Study of the Topology and Geometry of Deep Networks

CVPR 2018poster

The goal of this paper is to analyze the geometric properties of deep neural network image classifiers in the input space. We specifically study the topology of classification regions created by deep networks, as well as their associated decision boundary. Through a systematic empirical study, we sh…

Cited by 185SourcePDFScholar
2018

Robustness of Classifiers to Universal Perturbations: A Geometric Perspective

ICLR 2018poster

Deep networks have recently been shown to be vulnerable to universal perturbations: there exist very small image-agnostic perturbations that cause most natural images to be misclassified by such classifiers. In this paper, we provide a quantitative analysis of the robustness of classifiers to univer…

Cited by 66SourcePDFScholar
2018

Robustness of classifiers to uniform $\ell_p$ and Gaussian noise

AISTATS 2018poster

We study the robustness of classifiers to various kinds of random noise models. In particular, we consider noise drawn uniformly from the $\ell_p$ ball for $p ∈[1, ∞]$ and Gaussian noise with an arbitrary covariance matrix. We characterize this robustness to random noise in terms of the distance to…

Cited by 0SourcePDFScholar
2016

DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks

CVPR 2016poster

State-of-the-art deep neural networks have achieved impressive results on many image classification tasks. However, these same architectures have been shown to be unstable to small, well sought, perturbations of the images. Despite the importance of this phenomenon, no effective methods have been pr…

Cited by 6723PDFcodeScholar
2016

Robustness of classifiers: from adversarial to random noise

NeurIPS 2016poster

Several recent works have shown that state-of-the-art classifiers are vulnerable to worst-case (i.e., adversarial) perturbations of the datapoints. On the other hand, it has been empirically observed that these same classifiers are relatively robust to random noise. In this paper, we propose to stud…

Cited by 450SourcePDFScholar