Robust Design of Deep Neural Networks Against Adversarial Attacks Based on Lyapunov Theory
Arash Rahnama, André T. Nguyen, Edward Raff
Abstract
Deep neural networks (DNNs) are vulnerable to subtle adversarial perturbations applied to the input. These adversarial perturbations, though imperceptible, can easily mislead the DNN. In this work, we take a control theoretic approach to the problem of robustness in DNNs. We treat each individual layer of the DNN as a nonlinear system and use Lyapunov theory to prove stability and robustness locally. We then proceed to prove stability and robustness globally for the entire DNN. We develop empirically tight bounds on the response of the output layer, or any hidden layer, to adversarial perturbations added to the input, or to any preceding hidden layer. We show how the spectral norm of the weight matrix for an individual layer relates to Lyapunov properties of that layer, and consequently to the local and global stability and robustness of the DNN. Our results give new insights into how spectral norm regularization can mitigate the adversarial effects. Finally, we evaluate the power of our approach on a variety of data sets and network architectures and against some of the well-known adversarial attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- Defending Against Adversarial Attacks via Neural Dynamic SystemXiyuan Li, Xin Zou, Weiwei LiuNeurIPS 2022 · 23 citations
- Learning Diverse-Structured Networks for Adversarial RobustnessXuefeng Du, Jingfeng Zhang, Bo Han, Tongliang Liu et al.ICML 2021 · 22 citations
- Towards Robustness of Deep Neural Networks via RegularizationYao Li, Martin Renqiang Min, Thomas C. M. Lee, Wenchao Yu et al.ICCV 2021 · 8 citations
- Random Spiking Neural Networks are Stable and Spectrally SimpleErnesto Araya, Massimiliano Datres, Gitta KutyniokICLR 2026 · 1 citation
- Understanding and Improving Adversarial Robustness of Neural Probabilistic CircuitsWeixin Chen, Han ZhaoNeurIPS 2025 · 1 citation
Builds on1
Related papers
- Stable Neural ODE with Lyapunov-Stable Equilibrium Points for Defending Against Adversarial AttacksQiyu Kang, Yang Song, Qinxu Ding, Wee Peng TayNeurIPS 2021 · 130 citations
- Lyapunov-Stable Deep Equilibrium ModelsHaoyu Chu, Shikui Wei, Ting Liu, Yao Zhao et al.AAAI 2024 · 10 citations
- PAC-Bayesian Spectrally-Normalized Bounds for Adversarially Robust GeneralizationJiancong Xiao, Ruoyu Sun, Zhi-Quan LuoNeurIPS 2023 · 14 citations
- Adversarial Training is a Form of Data-dependent Operator Norm RegularizationKevin Roth, Yannic Kilcher, Thomas HofmannNeurIPS 2020 · 61 citations
- Fantastic Four: Differentiable and Efficient Bounds on Singular Values of Convolution LayersSahil Singla, Soheil FeiziICLR 2021 · 2 citations
