{"data":{"id":"10.48550/arxiv.1812.02606","type":"dois","attributes":{"doi":"10.48550/arxiv.1812.02606","prefix":"10.48550","suffix":"arxiv.1812.02606","identifiers":[{"identifier":"1812.02606","identifierType":"arXiv"}],"alternateIdentifiers":[{"alternateIdentifierType":"arXiv","alternateIdentifier":"1812.02606"}],"creators":[{"name":"Grosse, Kathrin","nameType":"Personal","givenName":"Kathrin","familyName":"Grosse","affiliation":[],"nameIdentifiers":[]},{"name":"Pfaff, David","nameType":"Personal","givenName":"David","familyName":"Pfaff","affiliation":[],"nameIdentifiers":[]},{"name":"Smith, Michael Thomas","nameType":"Personal","givenName":"Michael Thomas","familyName":"Smith","affiliation":[],"nameIdentifiers":[]},{"name":"Backes, Michael","nameType":"Personal","givenName":"Michael","familyName":"Backes","affiliation":[],"nameIdentifiers":[]}],"titles":[{"title":"The Limitations of Model Uncertainty in Adversarial Settings"}],"publisher":"arXiv","container":{},"publicationYear":2018,"subjects":[{"lang":"en","subject":"Cryptography and Security (cs.CR)","subjectScheme":"arXiv"},{"lang":"en","subject":"Machine Learning (cs.LG)","subjectScheme":"arXiv"},{"subject":"FOS: Computer and information sciences","subjectScheme":"Fields of Science and Technology (FOS)"},{"subject":"FOS: Computer and information sciences","schemeUri":"http://www.oecd.org/science/inno/38235147.pdf","subjectScheme":"Fields of Science and Technology (FOS)"}],"contributors":[],"dates":[{"date":"2018-12-06T15:33:46Z","dateType":"Submitted","dateInformation":"v1"},{"date":"2018-12-10T09:09:07Z","dateType":"Updated","dateInformation":"v1"},{"date":"2019-11-17T21:25:06Z","dateType":"Submitted","dateInformation":"v2"},{"date":"2019-11-19T01:18:28Z","dateType":"Updated","dateInformation":"v2"},{"date":"2018-12","dateType":"Available","dateInformation":"v1"},{"date":"2018","dateType":"Issued"}],"language":null,"types":{"ris":"GEN","bibtex":"misc","citeproc":"article","schemaOrg":"CreativeWork","resourceType":"Article","resourceTypeGeneral":"Preprint"},"relatedIdentifiers":[],"relatedItems":[],"sizes":[],"formats":[],"version":"2","rightsList":[{"rights":"arXiv.org perpetual, non-exclusive license","rightsUri":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/"}],"descriptions":[{"description":"Machine learning models are vulnerable to adversarial examples: minor perturbations to input samples intended to deliberately cause misclassification. While an obvious security threat, adversarial examples yield as well insights about the applied model itself. We investigate adversarial examples in the context of Bayesian neural network's (BNN's) uncertainty measures. As these measures are highly non-smooth, we use a smooth Gaussian process classifier (GPC) as substitute. We show that both confidence and uncertainty can be unsuspicious even if the output is wrong. Intriguingly, we find subtle differences in the features influencing uncertainty and confidence for most tasks.","descriptionType":"Abstract"},{"description":"Accepted to the Bayesian Deep Learning Workshop 2019 at NeurIPS. For longer version with more background, refer to previous version","descriptionType":"Other"}],"geoLocations":[],"fundingReferences":[],"xml":"PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0idXRmLTgiPz4KPHJlc291cmNlIHhtbG5zPSJodHRwOi8vZGF0YWNpdGUub3JnL3NjaGVtYS9rZXJuZWwtNCIgeG1sbnM6eHNpPSJodHRwOi8vd3d3LnczLm9yZy8yMDAxL1hNTFNjaGVtYS1pbnN0YW5jZSIgeHNpOnNjaGVtYUxvY2F0aW9uPSJodHRwOi8vZGF0YWNpdGUub3JnL3NjaGVtYS9rZXJuZWwtNCBodHRwOi8vc2NoZW1hLmRhdGFjaXRlLm9yZy9tZXRhL2tlcm5lbC00LjMvbWV0YWRhdGEueHNkIj4KICA8aWRlbnRpZmllciBpZGVudGlmaWVyVHlwZT0iRE9JIj4xMC40ODU1MC9BUlhJVi4xODEyLjAyNjA2PC9pZGVudGlmaWVyPgogIDxhbHRlcm5hdGVJZGVudGlmaWVycz4KICAgIDxhbHRlcm5hdGVJZGVudGlmaWVyIGFsdGVybmF0ZUlkZW50aWZpZXJUeXBlPSJhclhpdiI+MTgxMi4wMjYwNjwvYWx0ZXJuYXRlSWRlbnRpZmllcj4KICA8L2FsdGVybmF0ZUlkZW50aWZpZXJzPgogIDxjcmVhdG9ycz4KICAgIDxjcmVhdG9yPgogICAgICA8Y3JlYXRvck5hbWUgbmFtZVR5cGU9IlBlcnNvbmFsIj5Hcm9zc2UsIEthdGhyaW48L2NyZWF0b3JOYW1lPgogICAgICA8Z2l2ZW5OYW1lPkthdGhyaW48L2dpdmVuTmFtZT4KICAgICAgPGZhbWlseU5hbWU+R3Jvc3NlPC9mYW1pbHlOYW1lPgogICAgPC9jcmVhdG9yPgogICAgPGNyZWF0b3I+CiAgICAgIDxjcmVhdG9yTmFtZSBuYW1lVHlwZT0iUGVyc29uYWwiPlBmYWZmLCBEYXZpZDwvY3JlYXRvck5hbWU+CiAgICAgIDxnaXZlbk5hbWU+RGF2aWQ8L2dpdmVuTmFtZT4KICAgICAgPGZhbWlseU5hbWU+UGZhZmY8L2ZhbWlseU5hbWU+CiAgICA8L2NyZWF0b3I+CiAgICA8Y3JlYXRvcj4KICAgICAgPGNyZWF0b3JOYW1lIG5hbWVUeXBlPSJQZXJzb25hbCI+U21pdGgsIE1pY2hhZWwgVGhvbWFzPC9jcmVhdG9yTmFtZT4KICAgICAgPGdpdmVuTmFtZT5NaWNoYWVsIFRob21hczwvZ2l2ZW5OYW1lPgogICAgICA8ZmFtaWx5TmFtZT5TbWl0aDwvZmFtaWx5TmFtZT4KICAgIDwvY3JlYXRvcj4KICAgIDxjcmVhdG9yPgogICAgICA8Y3JlYXRvck5hbWUgbmFtZVR5cGU9IlBlcnNvbmFsIj5CYWNrZXMsIE1pY2hhZWw8L2NyZWF0b3JOYW1lPgogICAgICA8Z2l2ZW5OYW1lPk1pY2hhZWw8L2dpdmVuTmFtZT4KICAgICAgPGZhbWlseU5hbWU+QmFja2VzPC9mYW1pbHlOYW1lPgogICAgPC9jcmVhdG9yPgogIDwvY3JlYXRvcnM+CiAgPHRpdGxlcz4KICAgIDx0aXRsZT5UaGUgTGltaXRhdGlvbnMgb2YgTW9kZWwgVW5jZXJ0YWludHkgaW4gQWR2ZXJzYXJpYWwgU2V0dGluZ3M8L3RpdGxlPgogIDwvdGl0bGVzPgogIDxwdWJsaXNoZXI+YXJYaXY8L3B1Ymxpc2hlcj4KICA8cHVibGljYXRpb25ZZWFyPjIwMTg8L3B1YmxpY2F0aW9uWWVhcj4KICA8c3ViamVjdHM+CiAgICA8c3ViamVjdCB4bWw6bGFuZz0iZW4iIHN1YmplY3RTY2hlbWU9ImFyWGl2Ij5DcnlwdG9ncmFwaHkgYW5kIFNlY3VyaXR5IChjcy5DUik8L3N1YmplY3Q+CiAgICA8c3ViamVjdCB4bWw6bGFuZz0iZW4iIHN1YmplY3RTY2hlbWU9ImFyWGl2Ij5NYWNoaW5lIExlYXJuaW5nIChjcy5MRyk8L3N1YmplY3Q+CiAgICA8c3ViamVjdCBzdWJqZWN0U2NoZW1lPSJGaWVsZHMgb2YgU2NpZW5jZSBhbmQgVGVjaG5vbG9neSAoRk9TKSI+Rk9TOiBDb21wdXRlciBhbmQgaW5mb3JtYXRpb24gc2NpZW5jZXM8L3N1YmplY3Q+CiAgPC9zdWJqZWN0cz4KICA8ZGF0ZXM+CiAgICA8ZGF0ZSBkYXRlVHlwZT0iU3VibWl0dGVkIiBkYXRlSW5mb3JtYXRpb249InYxIj4yMDE4LTEyLTA2VDE1OjMzOjQ2WjwvZGF0ZT4KICAgIDxkYXRlIGRhdGVUeXBlPSJVcGRhdGVkIiBkYXRlSW5mb3JtYXRpb249InYxIj4yMDE4LTEyLTEwVDA5OjA5OjA3WjwvZGF0ZT4KICAgIDxkYXRlIGRhdGVUeXBlPSJTdWJtaXR0ZWQiIGRhdGVJbmZvcm1hdGlvbj0idjIiPjIwMTktMTEtMTdUMjE6MjU6MDZaPC9kYXRlPgogICAgPGRhdGUgZGF0ZVR5cGU9IlVwZGF0ZWQiIGRhdGVJbmZvcm1hdGlvbj0idjIiPjIwMTktMTEtMTlUMDE6MTg6MjhaPC9kYXRlPgogICAgPGRhdGUgZGF0ZVR5cGU9IkF2YWlsYWJsZSIgZGF0ZUluZm9ybWF0aW9uPSJ2MSI+MjAxOC0xMjwvZGF0ZT4KICA8L2RhdGVzPgogIDxyZXNvdXJjZVR5cGUgcmVzb3VyY2VUeXBlR2VuZXJhbD0iUHJlcHJpbnQiPkFydGljbGU8L3Jlc291cmNlVHlwZT4KICA8dmVyc2lvbj4yPC92ZXJzaW9uPgogIDxyaWdodHNMaXN0PgogICAgPHJpZ2h0cyByaWdodHNVUkk9Imh0dHA6Ly9hcnhpdi5vcmcvbGljZW5zZXMvbm9uZXhjbHVzaXZlLWRpc3RyaWIvMS4wLyI+YXJYaXYub3JnIHBlcnBldHVhbCwgbm9uLWV4Y2x1c2l2ZSBsaWNlbnNlPC9yaWdodHM+CiAgPC9yaWdodHNMaXN0PgogIDxkZXNjcmlwdGlvbnM+CiAgICA8ZGVzY3JpcHRpb24gZGVzY3JpcHRpb25UeXBlPSJBYnN0cmFjdCI+TWFjaGluZSBsZWFybmluZyBtb2RlbHMgYXJlIHZ1bG5lcmFibGUgdG8gYWR2ZXJzYXJpYWwgZXhhbXBsZXM6IG1pbm9yIHBlcnR1cmJhdGlvbnMgdG8gaW5wdXQgc2FtcGxlcyBpbnRlbmRlZCB0byBkZWxpYmVyYXRlbHkgY2F1c2UgbWlzY2xhc3NpZmljYXRpb24uIFdoaWxlIGFuIG9idmlvdXMgc2VjdXJpdHkgdGhyZWF0LCBhZHZlcnNhcmlhbCBleGFtcGxlcyB5aWVsZCBhcyB3ZWxsIGluc2lnaHRzIGFib3V0IHRoZSBhcHBsaWVkIG1vZGVsIGl0c2VsZi4gV2UgaW52ZXN0aWdhdGUgYWR2ZXJzYXJpYWwgZXhhbXBsZXMgaW4gdGhlIGNvbnRleHQgb2YgQmF5ZXNpYW4gbmV1cmFsIG5ldHdvcmsncyAoQk5OJ3MpIHVuY2VydGFpbnR5IG1lYXN1cmVzLiBBcyB0aGVzZSBtZWFzdXJlcyBhcmUgaGlnaGx5IG5vbi1zbW9vdGgsIHdlIHVzZSBhIHNtb290aCBHYXVzc2lhbiBwcm9jZXNzIGNsYXNzaWZpZXIgKEdQQykgYXMgc3Vic3RpdHV0ZS4gV2Ugc2hvdyB0aGF0IGJvdGggY29uZmlkZW5jZSBhbmQgdW5jZXJ0YWludHkgY2FuIGJlIHVuc3VzcGljaW91cyBldmVuIGlmIHRoZSBvdXRwdXQgaXMgd3JvbmcuIEludHJpZ3VpbmdseSwgd2UgZmluZCBzdWJ0bGUgZGlmZmVyZW5jZXMgaW4gdGhlIGZlYXR1cmVzIGluZmx1ZW5jaW5nIHVuY2VydGFpbnR5IGFuZCBjb25maWRlbmNlIGZvciBtb3N0IHRhc2tzLjwvZGVzY3JpcHRpb24+CiAgICA8ZGVzY3JpcHRpb24gZGVzY3JpcHRpb25UeXBlPSJPdGhlciI+QWNjZXB0ZWQgdG8gdGhlIEJheWVzaWFuIERlZXAgTGVhcm5pbmcgV29ya3Nob3AgMjAxOSBhdCBOZXVySVBTLiBGb3IgbG9uZ2VyIHZlcnNpb24gd2l0aCBtb3JlIGJhY2tncm91bmQsIHJlZmVyIHRvIHByZXZpb3VzIHZlcnNpb248L2Rlc2NyaXB0aW9uPgogIDwvZGVzY3JpcHRpb25zPgo8L3Jlc291cmNlPg==","url":"https://arxiv.org/abs/1812.02606","contentUrl":null,"metadataVersion":0,"schemaVersion":"http://datacite.org/schema/kernel-4","source":"mds","isActive":true,"state":"findable","reason":null,"viewCount":0,"viewsOverTime":[],"downloadCount":0,"downloadsOverTime":[],"referenceCount":0,"citationCount":0,"citationsOverTime":[],"partCount":0,"partOfCount":0,"versionCount":0,"versionOfCount":0,"created":"2022-03-01T15:26:07.000Z","registered":"2022-03-01T15:26:08.000Z","published":"2018","updated":"2022-03-01T15:26:08.000Z"},"relationships":{"client":{"data":{"id":"arxiv.content","type":"clients"}},"provider":{"data":{"id":"arxiv","type":"providers"}},"media":{"data":{"id":"10.48550/arxiv.1812.02606","type":"media"}},"references":{"data":[]},"citations":{"data":[]},"parts":{"data":[]},"partOf":{"data":[]},"versions":{"data":[]},"versionOf":{"data":[]}}}}