Probing, Improving, and Verifying Machine Learning Model Robustness
Name
Xiao-kaix-PhD-EECS-2022-thesis.pdf
Description
Thesis PDF
Size
26.65 MB
Format
Adobe PDF
Checksum (MD5)
6764ef4be0be2fa94b88d61171d40d76
Author(s)
Xiao, Kai Yuanqing
Advisor(s)
Mądry, Aleksander
Date Issued
September 2022
Publisher
Massachusetts Institute of Technology
Abstract
Machine learning models turn out to be brittle when faced with distribution shifts, making them hard to rely on in real-world deployment. This motivates developing methods that enable us to detect and alleviate such model brittleness, as well as to verify that our models indeed meet desired robustness guarantees.
This thesis presents a set of tools that help us detect model vulnerabilities and biases. This set comprises, on the one hand, a suite of new datasets that allow us to obtain a finer-grained understanding of model reliance on backgrounds. On the other hand, it involves 3DB, a framework that leverages photorealistic simulation, to probe model vulnerabilities to more varied distribution shifts.
In addition to identifying these vulnerabilities, we discuss interventions that can make models more robust to distribution shifts, including using more training data. As we demonstrate, indiscriminately using more auxiliary data is not always beneficial, and we thus develop dataset projection, a method to choose the "right" auxiliary data to use.
Finally, we show how to efficiently and formally verify that our models are robust to one of the most well-studied types of distribution shift: pixel-wise adversarial perturbations.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
In Copyright - Educational Use Permitted
Copyright MIT
Persistent DSpace Link