5f7202469b0f74aa.tex
1: \begin{abstract}
2: 
3:   This work provides theoretical and empirical evidence that
4:   invariance-inducing regularizers can increase predictive accuracy
5:   for worst-case spatial transformations (spatial \emph{robustness}).
6:   Evaluated on these \emph{adversarially} transformed examples, we
7:   demonstrate that adding regularization on top of standard or
8:   adversarial training reduces the relative error by 20\% for CIFAR10
9:   without increasing the computational cost.  This outperforms
10:   handcrafted networks that were explicitly designed to be
11:   spatial-equivariant. Furthermore, we observe for SVHN, known to have
12:   inherent variance in orientation, that robust training also improves
13:   standard accuracy on the test set. We prove that this no-trade-off
14:   phenomenon holds for adversarial examples from \emph{transformation}
15:   groups in the infinite data limit.
16:   
17:  \end{abstract}
18: