Robustness Guarantees for Adversarially Trained Neural Networks
Poorya Mianjy, Raman Arora
Abstract
We study robust adversarial training of two-layer neural networks as a bi-level optimization problem. In particular, for the inner loop that implements the adversarial attack during training using projected gradient descent (PGD), we propose maximizing a lower bound on the 0 / 1 -loss by reflecting a surrogate loss about the origin. This allows us to give a convergence guarantee for the inner-loop PGD attack. Furthermore, assuming the data is linearly separable, we provide precise iteration complexity results for end-to-end adversarial training, which holds for any width and initialization. We provide empirical evidence to support our theoretical results.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0e691e07-de4b-493b-b589-4e2b63681a00Cited by top-tier papers4
- Adversarial Training Should Be Cast as a Non-Zero-Sum GameAlexander Robey, Fabian Latorre, George J. Pappas, Hamed Hassani et al.ICLR 2024 · 16 citations
- Stability and Generalization of Adversarial Training for Shallow Neural Networks with Smooth ActivationKaibo Zhang, Yunjuan Wang, Raman AroraNeurIPS 2024 · 5 citations
- Benign Overfitting in Adversarial Training of Neural NetworksYunjuan Wang, Kaibo Zhang, Raman AroraICML 2024 · 3 citations
- Adversarially Robust Hypothesis Transfer LearningYunjuan Wang, Raman AroraICML 2024
Builds on6
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Revisiting and Advancing Fast Adversarial Training Through The Lens of Bi-Level OptimizationYihua Zhang, Guanhua Zhang, Prashant Khanduri, Mingyi Hong et al.ICML 2022 · 107 citations
- Over-parameterized Adversarial Training: An Analysis Overcoming the Curse of DimensionalityYi Zhang, Orestis Plevrakis, Simon S. Du, Xingguo Li et al.NeurIPS 2020 · 56 citations
- Implicit Bias of Gradient Descent based Adversarial Training on Separable DataYan Li, Ethan X. Fang, Huan Xu, Tuo ZhaoICLR 2020 · 40 citations
- Provable Generalization of SGD-trained Neural Networks of Any Width in the Presence of Adversarial Label NoiseSpencer Frei, Yuan Cao, Quanquan GuICML 2021 · 22 citations
Related papers
- Understanding and Increasing Efficiency of Frank-Wolfe Adversarial TrainingTheodoros Tsiligkaridis, Jay RobertsCVPR 2022 · 6 citations
- Mind the Box: l1-APGD for Sparse Adversarial Attacks on Image ClassifiersFrancesco Croce, Matthias HeinICML 2021 · 68 citations
- Towards Understanding the Dynamics of the First-Order AdversariesZhun Deng, Hangfeng He, Jiaoyang Huang, Weijie J. SuICML 2020 · 11 citations
- Attacks Which Do Not Kill Training Make Adversarial Learning StrongerJingfeng Zhang, Xilie Xu, Bo Han, Gang Niu et al.ICML 2020 · 452 citations
- On the Convergence of Certified Robust Training with Interval Bound PropagationYihan Wang, Zhouxing Shi, Quanquan Gu, Cho-Jui HsiehICLR 2022 · 11 citations
