We analyze the data-dependent capacity of neural networks and assess anomalies in inputs from the perspective of networks during inference. The notion of data-dependent capacity allows for analyzing the knowledge base of a model populated by learned features from training data. We define purview as the additional capacity necessary to characterize inference samples that differ from the training data. To probe the purview of a network, we utilize gradients to measure the amount of change required for the model to characterize the given inputs more accurately. To eliminate the dependency on ground-truth labels in generating gradients, we introduce confounding labels that are formulated by combining multiple categorical labels. We demonstrate that our gradient-based approach can effectively differentiate inputs that cannot be accurately represented with learned features. We utilize our approach in applications of detecting anomalous inputs, including out-of-distribution, adversarial, and corrupted samples. Our approach requires no hyperparameter tuning or additional data processing and outperforms state-of-the-art methods by up to 2.7%, 19.8%, and 35.6% of AUROC scores, respectively.
翻译:我们分析了神经网络的数据依赖容量,并从网络推理视角评估输入中的异常。数据依赖容量的概念允许分析由训练数据中学习特征填充的模型知识库。我们将视域定义为表征与训练数据不同的推理样本所需的额外容量。为探测网络的视域,我们利用梯度衡量模型更精确表征给定输入所需的变化量。为消除梯度生成中对真实标签的依赖,我们引入由多个分类标签组合而成的混淆标签。实验证明,我们的基于梯度的方法能有效区分那些无法用学习特征精确表征的输入。我们将该方法应用于检测异常输入(包括分布外样本、对抗样本和损坏样本)。该方法无需超参数调优或额外数据处理,在AUROC指标上分别以最高2.7%、19.8%和35.6%的涨幅超越现有最优方法。