Precise estimation of uncertainty in predictions for AI systems is a criticalfactor in ensuring trust and safety. Deep neural networks trained with aconventional method are prone to over-confident predictions. In contrast toBayesian neural networks that learn approximate distributions on weights toinfer prediction confidence, we propose a novel method, Information RobustDirichlet networks, that learn an explicit Dirichlet prior distribution onpredictive distributions by minimizing the expected $L_p$ norm of theprediction error and penalizing information flow associated with incorrectoutcomes. Properties of the new cost function are derived to indicate howimproved uncertainty estimation is achieved. Experiments using real datasetsshow that our technique outperforms by a large margin state-of-the-art neuralnetworks for estimating within-distribution and out-of-distributionuncertainty, and detecting adversarial examples.
Quick Read (beta)
Information Robust Dirichlet Networks for Predictive Uncertainty Estimation
Precise estimation of uncertainty in predictions for AI systems is a critical factor in ensuring trust and safety. Deep neural networks trained with a conventional method are prone to over-confident predictions. In contrast to Bayesian neural networks that learn approximate distributions on weights to infer prediction confidence, we propose a novel method, Information Robust Dirichlet networks, that learn an explicit Dirichlet prior distribution on predictive distributions by minimizing the expected norm of the prediction error and penalizing information flow associated with incorrect outcomes. Properties of the new cost function are derived to indicate how improved uncertainty estimation is achieved. Experiments using real datasets show that our technique outperforms by a large margin state-of-the-art neural networks for estimating within-distribution and out-of-distribution uncertainty, and detecting adversarial examples.
Deep learning systems have achieved state-of-the-art performance in various domains . The first successful applications of deep learning include large-scale object recognition  and machine translation [3, 4]. While further advances have achieved strong performance and often surpass human-level ability in computer vision [5, 6, 7], speech recognition [8, 9], medicine , bioinformatics , other aspects of deep learning are less well understood. Conventional neural networks (NNs) are overconfident in their predictions  and provide inaccurate predictive uncertainty . NNs have to be accurate, but also provide an indicator of when an error is likely to be made. Intepretability, robustness, and safety are becoming increasingly important as deep learning is deployed across various industries including healthcare, autonomous driving and cybersecurity.
Uncertainty modeling in deep learning is a crucial aspect that has been the topic of various Bayesian neural network (BNN) research studies [14, 15, 16, 17]. BNNs capture parameter uncertainty of the network by learning distributions on weights and estimate a posterior predictive distribution by approximate integration over these parameters. The non-linearities embedded in deep neural networks make the weight posterior intractable and several tractable approximations have been proposed and trained using variational inference [14, 15, 17, 16, 18], the Laplace approximation [19, 20], expectation propagation [21, 22], and Hamiltonian Monte Carlo . The success of approximate BNN methods depends on how well the approximate weight distributions match their true counterparts, and their computational complexity is determined by the degree of approximation. Most BNNs take more effort to implement and are harder to train in comparison to conventional NNs. Furthermore, approximate integration over the parameter uncertainties increases the test time due to posterior sampling, and yields an approximate predictive distribution using stochastic averaging. Thus, it is of interest to develop methods that provide good uncertainty estimates while reusing the training pipeline and maintaining scalability. To this end, a simple approach was proposed that combines NN ensembles with adversarial training to improve predictive uncertainty estimates in a non-Bayesian manner , but is copmutationally expensive. It is also known that deterministic NNs are brittle to adversarial attacks [25, 26]. Predictive uncertainty can be used to reason about neural network predictions and detect when a network is likely to make an error, identify anomalous examples, and detect adversarial attacks.
In this paper, we propose Information Robust Dirichlet (IRD) networks that deliver more accurate predictive uncertainty than other state-of-the-art methods by learning how likely class probability assignments are. Our method modifies the output layer of neural networks and the training loss, therefore maintaining computational efficiency and ease of implementation. The contributions are as follows. First, a new training loss based on minimizing the expected norm of the prediction error is proposed under which the prediction probabilities follow a Dirichlet distribution. A closed-form approximation to this loss is derived, under which a neural network is trained to infer the parameters of a Dirichlet distribution, effectively teaching neural networks to learn distributions over class probability vectors. Second, a regularization loss is used to align the Dirichlet distribution parameters to an information direction that minimizes information flow towards incorrect classes. Third, an analysis is provided that shows how properties of the new loss improve uncertainty estimation. Finally, we demonstrate on real datasets that our technique obtains unmatched success in terms of uncertainty estimation for correct and incorrect predictions, detection of out-of-distribution queries and adversarial attacks.
I-A Related Work
Recently, in [27, 28] the Dirichlet distribution was used to model distributions of class compositions and its parameters were learned by training deterministic neural networks. This approach yields closed-form predictive distributions and outperforms BNNs in uncertainty quantification for out-of-distribution and adversarial queries. However, uncertainty estimation performance for within-distribution queries was not studied and out-of-distribution and adversarial query uncertainty can be improved. The authors in  provide a limited analysis of their loss, and  lacks analysis that relates the Dirichlet concentration parameters with their loss and further proposes to use OOD data for learning what is anomalous biasing the predictive uncertainty of the models.
In contrast, we provide a more thorough analysis of our loss function that yields insights into how neural networks shape Dirichlet distributions on the simplex. Furthermore, our method assigns higher uncertainties to errors while maintaining high confidence for correct predictions, and improves upon uncertainty quantification for OOD and adversarial data.
II Learning Distributions on the Probability Simplex
II-A Probabilistic Framework
Given dataset , we model the class probability vectors for sample given by as random vectors drawn from a Dirichlet distribution conditioned on the input and weights . A neural network with input and output is trained to learn multinomial opinions using the Dirichlet distribution (see (1)). This model can also be interpreted as an explicit prior over class probability distributions .
The predictive uncertainty of a classification model trained over this dataset can be expressed as:
The terms above represent data uncertainty, , distribution uncertainty, , and model uncertainty, . The Bayesian hierarchy implies that model uncertainty affects distributional uncertainty, which as a result influence the data uncertainty estimates. In our framework, the additional level of distributional uncertainty is incorporated to control the information spread over the simplex by learning in a robust manner during the training procedure. This in turn regularizes the density to produce improved predictive uncertainty estimates.
Since the posterior is intractable, approximate variational inference methods may be used in similar spirit to [14, 16] to estimate it. In addition, ensemble approaches are computationally expensive. For clarity in this paper, we assume a point-estimate of the weight parameters is sufficient given a large training set and proper regularization control, which yields . This simplifying approximation was also made in recent works [27, 28].
Conventional NNs for classification trained with a cross-entropy loss with a softmax output layer provide a point estimate of the predictive class probabilities of each example and do not have a handle on the underlying uncertainty. Cross-entropy training can be probabilistically interpreted as maximum likelihood estimation, which cannot infer predictive distribution variance. The softmax layer also tends to inflate the predicted class likelihood due to the exponentiation involved and this tyep of training tends to produce overconfident wrong predictions.
II-B Dirichlet Distribution
Outputs of neural networks for classification tasks are probability vectors over classes. The basis of our approach lies in an explicit model of distributional uncertainty that controls the distribution of such probability vectors using the Dirichlet distribution [29, 30]. Given the probability simplex as , the Dirichlet distribution is a probability density function on vectors given by
where is the multivariate Beta function. It is characterized by concentration parameters here assumed to be larger than unity 11 1 The reason for this constraint is that the Dirichlet distribution becomes inverted for concentrating in the corners of the simplex and along its boundaries.. The concentration parameter may be interpreted as how likely a class is relative to others. In the special case of the all-ones vector, the distribution becomes uniform over the probability simplex (see Fig. 1(d)). The mean of the proportions is given by , where is the Dirichlet strength.
The Dirichlet distribution is conjugate to the multinomial distribution with posterior parameters updated as for a multinomial sample . For a single sample, , where is the index of the correct class. Marginals of the Dirichlet distribution are Beta random variables, with support on . The -th moment of the Beta distribution is given by
where is the univariate Beta function. A Dirichlet neural network’s output layer parametrizes the simplex distribution representing the spread of class assignment probabilities. The softmax classification layer is replaced by a softplus activation layer that outputs non-negative continuous values, obtaining
that parametrize the density . The posterior distribution is given by:
The concentration parameters determine the shape of the Dirichlet distribution on the probability simplex, as is visualized in Fig. 1 for . Fig. 1(a) shows a confident prediction characterized by low entropy, (b) shows a more challenging prediction that has higher uncertainty, (c) shows a prediction characterized by high data uncertainty due to class overlap, and (d) shows a flat Dirichlet distribution that arises for an out-of-distribution example.
Predictive entropy measures total uncertainty and may be decomposed into epistemic (or knowledge) uncertainty (arises due to model’s difficulty in understanding inputs) and aleatoric (or data) uncertainty (arises due to class-overlap and noise) , given by:
The mutual information between the labels and the class probability vector p, , captures epistemic uncertainty, and can be calculated by subtracting the expected data uncertainty from the total uncertainty:
This metric explicitly captures the spread due to distributional uncertainty and is particularly useful for detection of out-of-distribution and adversarial examples. A variation of it was used in the context of active learning .
II-C Classification Loss
Available are one-hot encoded labels of examples with correct class . Treating the Dirichlet distribution as a prior on the multinomial likelihood function , one can minimize the negated log-marginal likelihood:
or the Bayes risk of the cross-entropy loss:
where is the digamma function. It was observed in  that these loss functions generate excessively high belief masses for classes hurting quantification of uncertainty and are less stable than minimizing the sum of squares of prediction errors instead. This can be attributed to the nature of these loss functions encouraging the maximization of correct class likelihoods.
Unlike conventional cross-entropy training that only seeks to maximize the correct class likelihood, we propose a distance-based objective that minimizes the expected prediction error capturing errors across all classes simultaneously by learning the appropriate Dirichlet concentration parameters that govern the spread of class probability vectors. We propose to minimize the Bayes risk of the prediction error in space for , which is approximated using Jensen’s inequality as
This loss can interpolate between to norms, and as grows large we minimize an approximation to the maximum prediction error, e.g., , which is difficult to directly optimize. Jensen’s inequality yields a tractable upper bound for all values of , and the loss encompasses higher-order moments of the Dirichlet experiment generated by the NN as opposed to just the bias and variance for the case. In practice, is chosen to strike a balance between the correct prediction confidence and uncertainties of errors/out-of-distribution queries.
To calculate each term in , we note has a distribution due to mirror symmetry, and has distribution . Using the moment expression (2) for Beta random variables:
The following theorem shows that the loss function has the correct behavior as the information flow increases towards the correct class which is consistent when an image sample of that class is observed in a Bayesian Dirichlet experiment and hyperparameters are incremented (see Sec. II-B).
For a given sample with correct label , the loss function is strictly convex and decreases as increases (and increases when decreases).
Theorem 1 shows that our objective function encourages the learned distribution of probability vectors to concentrate towards the correct class, consistent with Dirichlet sampling experiments. While increasing information flow towards the correct class reduces the loss, it is also important for the loss to capture elements of incorrect classes. It is expected that increasing information flow towards incorrect classes increases uncertainty. The next result shows that through our loss function the model avoids assigning high concentration parameters to incorrect classes as the model cannot explain observations that are assigned incorrect outcomes.
For a given sample with correct label , the loss function is increasing in for any as grows.
Theorem 2 implies that our loss function leads the model to push the distribution of class probability vectors away from incorrect classes.
II-D Information Regularization Loss
The classification loss can discover interesting patterns in the data to achieve high classification accuracy. However, the network may learn that certain patterns lead to strong information flow towards incorrect classes, e.g., a common pattern of one correct class might contribute to a large associated with an incorrect class. While for accuracy this might not be an issue as long as is larger than the incorrect , it does affect its predictive uncertainty. Thus, it is of interest to minimize the contributions of concentration parameters associated with incorrect outcomes.
Given the auxiliary vector formed by nulling out the correct class concentration parameter , we minimize the following distance function that aligns the concentration parameter vector towards unity:
where is the polygamma function of order , and denotes the Fisher information matrix . We remark that (3) is not a quadratic function in due to the nonlinearity of the polygamma functions and the fact that terms are tied together through the constraint . This regularization is related to a local approximation of the Rényi information divergence [32, 33] of the Dirichlet distribution from the uniform Dirichlet given by
in the local regime . This approximation follows from  (p. 2472) after using the second-order Taylor’s expansion and substituting the Fisher information matrix . The next theorem shows a desirable monotonicity property of the information regularization loss (3).
The information regularization loss given in (3) is increasing in for .
The total loss to be minimized, per example, is:
where is a nonnegative parameter controlling the tradeoff between minimizing the approximate Bayes risk and the information regularization penalty. The total loss is summed over a batch of training samples . Training is performed using minibatches with increasing using an annealing schedule, e.g., for for rate parameter (e.g. ) and for . The parameter should be chosen large enough to allow the network to learn interesting features useful for classification and avoid incorporating the regularization effect too early which may lead to learning difficulties.
Theorem 3 combined with Theorem 2 imply that the strength of concentration parameters associated with misleading outcomes is expected to decrease during training. This preferable behavior of our objective function leads to higher uncertainties for misclassifications as the concentration parameters are all aimed to be minimized instead of allowing one to be much larger than others.
III Experimental Results
All experiments are implemented in Tensorflow  and the Adam  optimizer was used for training. As recent prior works [27, 28] have shown Dirichlet NNs outperform BNNs on several benchmark image datasets, we mainly focus on comparing our method with these Dirichlet NNs trained with different loss functions. Comparisons are made with the following methods: (a) L2 corresponds to deterministic neural network with softmax output and weight decay, (b) Dropout is the uncertainty estimation method of , (c) EDL is the evidential approach of , (d) RKLPN is the reverse KL divergence-based prior network method of , and (e) IRD is our proposed technique.
III-A Fashion-MNIST Dataset
The LeNet CNN architecture with and filters of size is used for the Fashion-MNIST dataset  with hidden units at the dense layer. The training set contains digits and the testing set contains . The results were generated with . Table I shows the test accuracy on MNIST for these methods; IRD is shown to be competitive assigning low uncertainty to correct predictions and high uncertainty to errors. In general, a small accuracy loss is expected as the NN is trained so that data examples near the decision boundary (likely errors) lie in a high-uncertainty region that might affect predictions of nearby data; this can be mitigated by adjusting or . However, our results show that accuracy loss is not significant and OOD/adversarial uncertainty quantification improves upon prior methods while maintaining low uncertainty on correct predictions.
|Method||Accuracy||Median %Max-Entropy: Correct||Median %Max-Entropy: Errors|
To measure within-distribution uncertainty, Fig. 2 shows the distribution of entropies of predictive distributions for correct and misclassified examples across competing methods. The overconfidence of conventional L2 NNs is evident since the distribution mass of correct and wrong predictions is concentrated on lower uncertainties. The Dirichlet-based methods, EDL and RKLPN, tend to sacrifice correct class confidence for providing higher uncertainties on misclassified examples. IRD offers a drastic improvement over all methods with of the misclassified samples falling within of the max-entropy (), as opposed to and of the misclassified samples of the RKLPN and EDL methods respectively.
To evaluate out-of-distribution uncertainty quantification, the trained model on Fashion-MNIST is tested with image data from different datasets. Specifically, IRD is tested on notMNIST  which contains only English letters, and OmniGlot  which contains characters from multiple alphabets, serving as out-of-distribution data. The uncertainty is expected to be high for all such images as they do not fit into any trained category. Figures 3 and 4 shows the empirical CDF of the predictive entropy and mutual information. CDF curves close to the bottom right are more desirable as higher entropy is desired for all predictions. IRD is much more tightly concentrated towards higher entropy values; for notMNIST/OmniGlot, an impressive / of images have entropy larger than of the max-entropy, while EDL and PN have / and / approximately.
Adversarial uncertainty quantification on Fashion-MNIST was also evaluated. Fig. 5 shows the adversarial performance when each model is evaluated using adversarial examples generated with the Fast Gradient Sign method (FGSM)  for different noise values , i.e., . We observe that IRD achieves higher entropy on adversarial examples as increases than other methods while achieving a lower average predictive entropy for due to the higher confidence of correct predictions. Interestingly, a large entropy is assigned to misclassified samples as Fig. 2 shows.
III-B CIFAR-10 Dataset
A VGG-based CNN architecture consisting of three filter blocks with filters respectively with filter sizes was used for the CIFAR-10 dataset  with hidden units at the dense layer. The training/testing set is made up of / training examples. Regularization parameter was adopted with . Data augmentation, dropout and batch-normalization was used for all methods to mitigate overfitting. Table II shows the test accuracy on CIFAR-10 for these methods; IRD is shown to be competitive assigning low uncertainty to correct predictions and high uncertainty to errors.
|Method||Accuracy||Median %Max-Entropy: Correct||Median %Max-Entropy: Errors|
Within-distribution uncertainty quantification is evaluated in Fig. 6 which shows the distribution of entropies of predictive distributions for correct and misclassified examples across competing methods. Similar to the previous set of results, conventional L2 NNs yield overconfident predictions and EDL and RKLPN sacrifice correct class confidence for providing higher uncertainties on misclassified examples. IRD offers an improvement over all methods as the tail of the distribution of predictive entropies associated with misclassified examples is more heavily concentrated on higher values, while maintaining an improved correct prediction confidence over other Dirichlet neural networks.
For out-of-distribution testing, IRD is tested on Tiny-ImageNet  which contains a small subset of ILSVRC spanning 200 image classes, and SVHN  which contains street view house numbers. The uncertainty is expected to be high for all such images as they do not fit into any trained category. Figures 7 and 8 show the empirical CDF of the predictive entropy and mutual information. IRD is shown to improve upon competing methods as it concentrates more heavily towards higher entropy and mutual information values. The benefit is observed for both uncertainty metrics.
The adversarial performance for CIFAR-10 is shown in Fig. 9 under FGSM adversarial attacks as a function of noise . It is observed that IRD starts at low predictive entropy/mutual information and quickly increases its uncertainty as more adversarial noise is added in the system and the image moves farther away from the data manifold.
In this work, we presented a new method for training Dirichlet neural networks that are aware of the uncertainty associated with predictions. Our training objective fits predictive distributions to data using a classification loss that minimizes the expected prediction error measured in space, and an information regularization loss that penalizes information flow towards incorrect classes. We derived closed-form expressions for our training loss and desirable properties on how improved uncertainty estimation is achieved. Experimental results were shown on image classification tasks, highlighting improvements in predictive uncertainty estimation for within-distribution, out-of-distribution and adversarial queries made by our method over conventional neural networks with weight decay, Bayesian neural networks, and other recent Dirichlet networks trained with different loss functions.
We make use of the following lemmas in the proofs.
Consider the digamma function . Assuming and , the following inequality strictly holds:
Furthermore, we have .
Since , we can write and for some . Upon substitution of the Gauss integral representation (here is the Euler-Mascheroni constant), we have:
which is strictly positive since the integrand is positive for . Using the integral representation again, the inequality is equivalent to:
which holds since the integrand is positive due to an . The limit of follows from the asymptotic expansion , which yields as . This concludes the proof. ∎
Consider the polygamma function of order 1 . Assuming and , the following inequality strictly holds:
Proceeding similarly as in the Proof of Lemma 1, we write and for some . Upon substitution of the integral representation , we have:
which is strictly negative since the integrand is negative for . Using the integral representation again, the inequality is equivalent to:
which holds true since for . This concludes the proof. ∎
Proof of Theorem 1
Taking the logarithm of , we have:
where the second term is independent of . Letting the first term be denoted as , it suffices to show is strictly convex and decreasing in .
Proof of Theorem 2
Consider a concentration parameter corresponding to an incorrect class, i.e., . Define the ratio of Gamma functions as:
This function is positive, increasing and convex with derivative given by:
where we used the relation and defined
From Lemma 1, it follows that which implies is increasing.
Since is a continuous increasing function, it suffices to show the objective is increasing, given by . The derivative is then calculated as:
The condition is equivalent to:
Upon substituting the expression (4), this condition becomes:
From Lemma 1, it follows that and . In addition, the functions and are both increasing as grows. Using these results and the fact that as grows (due to Lemma 1), it follows that the inequality (5) holds true for large . Thus, we conclude that the loss function is increasing as gets large. The proof is complete. ∎
An illustration of Theorem 2 is shown in Fig. 10 below. An approximate loss function is also shown due to , from which we obtain the approximation . This approximation to the loss behaves similarly. Despite the initial dip, the loss is increasing as increases. We remark that the loss is neither convex nor concave in .
Proof of Theorem 3
Consider as a function of for some . Then, it may be decomposed as where
The first term is an increasing function since is increasing for any . The second term is also increasing since
which follows from the integral representation . ∎
-  Y. LeCun, Y. Bengio, and G. Hinton, “Deep Learning,” Nature, vol. 521, no. 7533, pp. 436–444, 2015.
-  A. Krizhevsky, I. Sutskever, and G. E. Hinton, “ImageNet classification with deep convolutional neural networks,” in Advances in Neural Information Processing Systems (NIPS), 2012.
-  I. Sutskever, O. Vinyals, and Q. V. Le, “Sequence to sequence learning with neural networks,” in Advances in Neural Information Processing Systems, 2014.
-  Y. Wu et al., “Google‘s neural machine translation system: Bridging the gap between human and machine translation,” Tech. Rep., 2016, arXiv:1609.08144.
-  R. Geirhos, C. R. M. Temme, J. Rauber, M. Bethge, and F. A. Wichmann, “Generalization in humans and deep neural networks,” in Advances in Neural Information Processing Systems, 2018.
-  K. He, X. Zhang, S. Ren, and J. Sun, “Delving Deep into Rectifiers: Surpassing Human-level Performance on ImageNet classification,” in IEEE International Conference on Computer Vision (ICCV), December 2015.
-  D. C. Ciresan, U. Meier, J. Masci, and J. Schmidhuber, “Multi-column deep neural network for traffic sign classification,” Neural Networks, vol. 32, pp. 333–338, 2012.
-  W. Xiong, J. Droppo, X. Huang, F. Seide, M. L. Seltzer, A. Stolcke, D. Yu, and G. Zweig, “Toward Human Parity in Conversational Speech Recognition,” IEEE Transactions on Audio, Speech, and Language Processing, vol. 25, no. 12, pp. 2410–2423, December 2017.
-  G. Hinton, L. Deng et al., “Deep neural networks for acoustic modeling in speech recognition: The shared views of four research groups,” IEEE Signal Processing Magazine, vol. 29, no. 6, pp. 82–97, 2012.
-  D. Wang, A. Khosla, R. Gargeya, H. Irshad, and A. H. Beck, “Deep Learning for Identifying Metastatic Breast Cancer,” Tech. Rep., June 2016, arXiv:1606.05718.
-  B. Alipanahi, A. Delong, M. T. Weirauch, and B. J. Frey, “Predicting the sequence specificities of DNA-and RNA-binding proteins by deep learning,” Nature biotechnology, vol. 33, no. 8, pp. 831–838, 2015.
-  C. Guo, G. Pleiss, Y. Sun, and K. Q. Weinberger, “On Calibration of Modern Neural Networks,” in International Conference on Machine Learning, 2017.
-  C. Louizos and M. Welling, “Multiplicative Normalizing Flows for Variational Bayesian Neural Networks,” in International Conference on Machine Learning (ICML), 2017.
-  C. Blundell, J. Cornebise, K. Kavukcuoglu, and D. Wierstra, “Weight Uncertainty in Neural Networks,” in International Conference on Machine Learning (ICML), 2015.
-  D. P. Kingma, T. Salimans, and M. Welling, “Variational dropout and the local reparameterization trick,” in Advances in Neural Information Processing (NIPS), 2015.
-  Y. Gal and Z. Ghahramani, “Dropout as a Bayesian Approximation: Representing Model Uncertainty in Deep Learning,” in International Conference on Machine Learning (ICML), 2016.
-  D. Molchanov, A. Ashukha, and D. Vetrov, “Variational dropout sparsifies deep neural networks,” in International Conference on Machine Learning (ICML), 2017.
-  Y. Li and Y. Gal, “Dropout inference in Bayesian neural networks with alpha-divergences,” in International Conference on Machine Learning, 2017.
-  D. J. MacKay, “A practical Bayesian framework for backpropagation networks,” Neural Computation, vol. 4, no. 3, pp. 448–472, 1992.
-  H. Ritter, A. Botev, and D. Barber, “A Scalable Laplace Approximation for Neural Networks,” in International Conference on Learning Representations, 2018.
-  J. M. Hernandez-Lobato and R. P. Adams, “Probabilistic backpropagation for scalable learning of bayesian neural networks,” in International Conference on Machine Learning, 2015.
-  S. Sun, C. Chen, and L. Carin, “Learning Structured Weight Uncertainty in Bayesian Neural Networks,” in International Conference on Artificial Intelligence and Statistics (AISTATS), 2017.
-  T. Chen, E. Fox, and C. Guestrin, “Stochastic Gradient Hamiltonian Monte Carlo,” in International Conference on Machine Learning, 2014.
-  B. Lakshminarayanan, A. Pritzel, and C. Blundell, “Simple and Scalable Predictive Uncertainty Estimation using Deep Ensembles,” in Advances in Neural Information Processing Systems, 2017.
-  I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and Harnessing Adversarial Examples,” in International Conference for Learning Representations, 2014.
-  A. Kurakin, I. J. Goodfellow, and S. Bengio, “Adversarial Machine Learning at Scale,” in International Conference for Learning Representations, 2017.
-  M. Sensoy, L. Kaplan, and M. Kandemir, “Evidential Deep Learning to Quantify Classification Uncertainty,” in Advances in Neural Information Processing Systems (NIPS) 31, 2018.
-  A. Malinin and M. Gales, “Reverse KL-Divergence Training of Prior Networks: Improved Uncertainty and Adversarial Robustness,” Tech. Rep., 2019, arXiv:1905.13472.
-  J. G. Mauldon, “A generalization of the Beta-distributions,” Annals of Mathematical Statistics, vol. 30, pp. 502–520, 1959.
-  J. E. Mosimann, “On the compound multinomial distribution, the multivariate beta-distribution, and correlations among proportions,” Biometrika, vol. 49, pp. 65–82, 1962.
-  N. Houlsby, F. Huszar, Z. Ghahramani, and M. Lengyel, “Bayesian Active Learning for Classification and Preference Learning,” Tech. Rep., 2011, arXiv:1112.5745.
-  A. Rényi, “On measures of entropy and information,” in Fourth Berkeley Symposium on Mathematical Statistics and Probability, Volume 1: Contributions to the Theory of Statistics, 1961, pp. 547–561.
-  T. V. Erven and P. Harremos, “Rényi divergence and Kullback-Leibler divergence,” IEEE Transactions on Information Theory, vol. 60, no. 7, pp. 3797–3820, 2014.
-  D. Haussler and M. Opper, “Mutual Information, Metric Entropy and Cumulative Relative Entropy Risk,” The Annals of Statistics, vol. 25, no. 6, pp. 2451–2492, 1997.
-  M. Abadi, P. Barham, J. Chen, Z. Chen, A. Davis, J. Dean, M. Devin, S. Ghemawat, G. Irving, M. Isard, M. Kudlur, J. Levenberg, R. Monga, S. Moore, D. G. Murray, B. Steiner, P. Tucker, V. Vasudevan, P. Warden, M. Wicke, Y. Yu, and X. Zheng, “Tensorflow: A system for large-scale machine learning,” in Proceedings of the 12th USENIX Conference on Operating Systems Design and Implementation, ser. OSDI’16. Berkeley, CA, USA: USENIX Association, 2016, pp. 265–283. [Online]. Available: http://dl.acm.org/citation.cfm?id=3026877.3026899
-  D. P. Kingma and J. Ba, “Adam: A Method for Stochastic Optimization,” in International Conference for Learning Representations, 2015.
-  H. Xiao, K. Rasul, and R. Vollgraf. (2017) Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms.
-  Y. Bulatov. (2011) notMNIST dataset. [Online]. Available: http://yaroslavvb.com/upload/notMNIST/
-  B. Lake, R. Salakhutdinov, and J. B. Tenenbaum. (2015) OmniGlot dataset. [Online]. Available: https://github.com/brendenlake/omniglot
-  A. Krizhevsky. The CIFAR-10 Dataset. [Online]. Available: https://www.cs.toronto.edu/~kriz/cifar.html
-  F.-F. Li, J. Johnson, and S. Yeung. (2017) Tiny ImageNet. [Online]. Available: http://cs231n.stanford.edu/tiny-imagenet-200.zip
-  Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng. (2011) Reading Digits in Natural Images with Unsupervised Feature Learning. [Online]. Available: http://ufldl.stanford.edu/housenumbers/