blob: efe006009f0b8dd42a611ef73231102efa9bffa7 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
|
\begin{figure}
\centering
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/egd/census/census_egd_attack_hard_race.pdf}
\caption{Census (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/egd/census/census_egd_attack_hard_sex.pdf}
\caption{Census (sex)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/egd/compas/compas_egd_attack_hard_race.pdf}
\caption{Compas (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/egd/compas/compas_egd_attack_hard_sex.pdf}
\caption{Compas (sex)}
\end{subfigure}
\centering
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/egd/meps/meps_egd_attack_hard_race.pdf}
\caption{Meps (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/egd/meps/meps_egd_attack_hard_sex.pdf}
\caption{Meps (sex)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/egd/lfw/lfw_egd_attack_hard_race.pdf}
\caption{Lfw (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/egd/lfw/lfw_egd_attack_hard_sex.pdf}
\caption{Lfw (sex)}
\end{subfigure}
\caption{For \AIAHard, we observe that EGD reduces the attack accuracy to random guess ($\sim$50\%)}
\label{fig:AdaptAIAEGD}
\end{figure}
\begin{figure}[!htb]
\centering
\footnotesize
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_race.pdf}
\caption{Census (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_soft_experimental_sex.pdf}
\caption{Census (sex)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_race.pdf}
\caption{Compas (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_soft_experimental_sex.pdf}
\caption{Compas (sex)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_race.pdf}
\caption{Meps (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_soft_experimental_sex.pdf}
\caption{Meps (sex)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_race.pdf}
\caption{Lfw (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_soft_experimental_sex.pdf}
\caption{Lfw (sex)}
\end{subfigure}
\caption{For both \AIASoft and \AIAHard, Adversarial debisaing reduces the attack accuracy to random guess ($\sim$50\%). For \AIAHard, the theoretical bound on attack accuracy matches with the empirical results.}
\label{fig:AdaptAIADebias}
\end{figure}
\begin{figure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_hard_race.pdf}
\caption{Census (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/census/census_advdeb_attack_hard_sex.pdf}
\caption{Census (sex)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_race.pdf}
\caption{Compas (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/compas/compas_advdeb_attack_hard_sex.pdf}
\caption{Compas (sex)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_race.pdf}
\caption{Meps (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/meps/meps_advdeb_attack_hard_sex.pdf}
\caption{Meps (sex)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_race.pdf}
\caption{Lfw (race)}
\end{subfigure}
\begin{subfigure}{0.24\linewidth}
\includegraphics[width=\linewidth]{ACSAC/figures/advdebias/lfw/lfw_advdeb_attack_hard_sex.pdf}
\caption{Lfw (sex)}
\end{subfigure}
\caption{adverarial debiasing hard}
\label{fig:aia-adv-hard}
\end{figure}
|