Adversarial Examples for k-Nearest Neighbor Classifiers Based on Higher-Order Voronoi Diagrams

11/19/2020
by   Chawin Sitawarin, et al.
24

Adversarial examples are a widely studied phenomenon in machine learning models. While most of the attention has been focused on neural networks, other practical models also suffer from this issue. In this work, we propose an algorithm for evaluating the adversarial robustness of k-nearest neighbor classification, i.e., finding a minimum-norm adversarial example. Diverging from previous proposals, we take a geometric approach by performing a search that expands outwards from a given input point. On a high level, the search radius expands to the nearby Voronoi cells until we find a cell that classifies differently from the input point. To scale the algorithm to a large k, we introduce approximation steps that find perturbations with smaller norm, compared to the baselines, in a variety of datasets. Furthermore, we analyze the structural properties of a dataset where our approach outperforms the competition.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/20/2019

On the Robustness of Deep K-Nearest Neighbors

Despite a large amount of attention on adversarial examples, very few wo...
research
06/23/2019

Defending Against Adversarial Examples with K-Nearest Neighbor

Robustness is an increasingly important property of machine learning mod...
research
11/01/2018

On the Geometry of Adversarial Examples

Adversarial examples are a pervasive phenomenon of machine learning mode...
research
09/27/2021

The edge labeling of higher order Voronoi diagrams

We present an edge labeling of order-k Voronoi diagrams, V_k(S), of poin...
research
05/02/2019

Adversarial Training with Voronoi Constraints

Adversarial examples are a pervasive phenomenon of machine learning mode...
research
05/20/2022

Getting a-Round Guarantees: Floating-Point Attacks on Certified Robustness

Adversarial examples pose a security risk as they can alter a classifier...
research
06/10/2019

Evaluating the Robustness of Nearest Neighbor Classifiers: A Primal-Dual Perspective

We study the problem of computing the minimum adversarial perturbation o...

Please sign up or login with your details

Forgot password? Click here to reset