Adversarial Robustness on In- and Out-Distribution Improves Explainability

Neural networks have led to major improvements in image classification but\nsuffer from being non-robust to adversarial changes, unreliable uncertainty\nestimates on out-distribution samples and their inscrutable black-box\ndecisions. In this work we propose RATIO, a training procedure for Robustness\nvia Adversarial Training on In- and Out-distribution, which leads to robust\nmodels with reliable and robust confidence estimates on the out-distribution.\nRATIO has similar generative properties to adversarial training so that visual\ncounterfactuals produce class specific features. While adversarial training\ncomes at the price of lower clean accuracy, RATIO achieves state-of-the-art\n$l_2$-adversarial robustness on CIFAR10 and maintains better clean accuracy.\n

Paper

References (76)

Scroll for more · 38 remaining

Similar papers

© 2026 NYSGPT2525 LLC