Key points are not available for this paper at this time.
Despite achieving impressive performance, state-of-the-art classifiers remain vulnerable to small, imperceptible, adversarial perturbations. This has proven empirically to be very intricate to address. In this, we study the phenomenon of adversarial perturbations under the that the data is generated with a smooth generative model. We derive upper bounds on the robustness to perturbations of any function, and prove the existence of adversarial perturbations transfer well across different classifiers with small risk. Our analysis the robustness also provides insights onto key properties of generative, such as their smoothness and dimensionality of latent space. We with numerical experimental results showing that our bounds provide baselines to the maximal achievable robustness on several datasets.
Fawzi et al. (Fri,) studied this question.