Curse of co-Dimensionality: Explaining Adversarial Examples by Embedding Geometry of Data Manifold

Hajime Tasaki, Yuji Kaneko, Jinhui Chao · 2022 26th International Conference on Pattern Recognition (ICPR) · 2022

It is widely known that adversarial examples cause misclassification in classifiers trained by deep learning. In spite of numerous previous researches, the phenomenon has not been well understood and clearly explained, hence there is no effective countermeasures available now. In this research, instead of exploring on neural networks and their training algorithms, we focus on the training data of the classifier, as submanifolds embedded in Euclidean space. We show that occurrence of adversarial examples is due to the embedding structure of the data manifold in the data space, specifically existence of so-called co-dimension of the data manifold. In particular, they lie in the orthogonal complementary subspaces of the tangent spaces of the data manifold. The theory is then verified on adversarial examples by visualization in 3D space and analysis in high dimensional space.

Read the paper · More papers on PaperTik