The Pitfalls of Simplicity Bias in Neural Networks

Several works have proposed Simplicity Bias (SB)---the tendency of standard training procedures such as Stochastic Gradient Descent (SGD) to find simple models---to justify why neural networks generalize well [Arpit et al. 2017, Nakkiran et al. 2019, Soudry et al. 2018]. However, the precise notion of simplicity remains vague. Furthermore, previous settings that use SB to theoretically justify why neural networks generalize well do not simultaneously capture the non-robustness of neural networks---a widely observed phenomenon in practice [Goodfellow et al. 2014, Jo and Bengio 2017]. We attempt to reconcile SB and the superior standard generalization of neural networks with the non-robustness observed in practice by designing datasets that (a) incorporate a precise notion of simplicity, (b) comprise multiple predictive features with varying levels of simplicity, and (c) capture the non-robustness of neural networks trained on real data. Through theory and empirics on these datasets, we make four observations: (i) SB of SGD and variants can be extreme: neural networks can exclusively rely on the simplest feature and remain invariant to all predictive complex features. (ii) The extreme aspect of SB could explain why seemingly benign distribution shifts and small adversarial perturbations significantly degrade model performance. (iii) Contrary to conventional wisdom, SB can also hurt generalization on the same data distribution, as SB persists even when the simplest feature has less predictive power than the more complex features. (iv) Common approaches to improve generalization and robustness---ensembles and adversarial training---can fail in mitigating SB and its pitfalls. Given the role of SB in training neural networks, we hope that the proposed datasets and methods serve as an effective testbed to evaluate novel algorithmic approaches aimed at avoiding the pitfalls of SB.

Measuring the tendencyof CNNs to Learn Surfac…Measuring the tendency of CNNs to Learn Surface Statistical RegularitiesDensely ConnectedConvolutional NetworksDensely Connected Convolutional NetworksTowards Deep LearningModels Resistant to…Towards Deep Learning Models Resistant to Adversarial AttacksFeature Squeezing:Detecting Adversarial…Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksEnhancing TheReliability of…Enhancing The Reliability of Out-of-distribution Image Detection in Neural NetworksObfuscated GradientsGive a False Sense of…Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial ExamplesSGD on Neural NetworksLearns Functions of…SGD on Neural Networks Learns Functions of Increasing ComplexityAre adversarial examplesinevitable?Are adversarial examples inevitable?Improving AdversarialRobustness of Ensembles…Improving Adversarial Robustness of Ensembles with Diversity TrainingThe Odds are Odd: AStatistical Test for…The Odds are Odd: A Statistical Test for Detecting Adversarial ExamplesFast is better thanfree: Revisiting…Fast is better than free: Revisiting adversarial trainingNatural AdversarialExamplesNatural Adversarial ExamplesWhat shapes featurerepresentations?…What shapes feature representations? Exploring datasets, architectures, and trainingShortcut Learning inDeep Neural NetworksShortcut Learning in Deep Neural NetworksGradient Starvation: ALearning Proclivity in…Gradient Starvation: A Learning Proclivity in Neural NetworksAdversarialPerturbations Are Not S…Adversarial Perturbations Are Not So Weird: Entanglement of Robust and Non-Robust Features in Neural Network ClassifiersA Little Robustness Goesa Long Way: Leveraging…A Little Robustness Goes a Long Way: Leveraging Universal Features for Targeted Transfer AttacksBetter Safe Than Sorry:Preventing Delusive…Better Safe Than Sorry: Preventing Delusive Adversaries with Adversarial TrainingCan Subnetwork StructureBe the Key to…Can Subnetwork Structure Be the Key to Out-of-Distribution Generalization?Feature blindness: Achallenge for…Feature blindness: A challenge for understanding and modelling visual object recognitionA Too-Good-to-be-TruePrior to Reduce Shortcu…A Too-Good-to-be-True Prior to Reduce Shortcut RelianceEvading the SimplicityBias: Training a Divers…Evading the Simplicity Bias: Training a Diverse Set of Models Discovers Solutions with Superior OOD GeneralizationSimple data balancingachieves competitive…Simple data balancing achieves competitive worst-group-accuracyThe Low-Rank SimplicityBias in Deep NetworksThe Low-Rank Simplicity Bias in Deep NetworksThe Pitfalls ofSimplicity Bias in…The Pitfalls of Simplicity Bias in Neural Networks過去の参考文献中心の論文この論文を引用する論文古い新しい

ノードをクリックするとフォーカスを固定、空白をクリックすると本論文に戻ります。ホバーで一時的にプレビューできます。各ノードのページはタイトルから開けます。