Second-Order Provable Defenses against Adversarial Attacks
Sahil Singla, Soheil Feizi
Abstract
A robustness certificate is the minimum distance of a given input to the decision boundary of the classifier (or its lower bound). For any input perturbations with a magnitude smaller than the certificate value, the classification output will provably remain unchanged. Exactly computing the robustness certificates for neural networks is difficult since it requires solving a non-convex optimization. In this paper, we provide computationally-efficient robustness certificates for neural networks with differentiable activation functions in two steps. First, we show that if the eigenvalues of the Hessian of the network are bounded, we can compute a robustness certificate in the norm efficiently using convex optimization. Second, we derive a computationally-efficient differentiable upper bound on the curvature of a deep network. We also use the curvature bound as a regularization term during the training of the network to boost its certified robustness. Putting these results together leads to our proposed Curvature-based Robustness Certificate (CRC) and Curvature-based Robust Training (CRT). Our numerical results show that CRT leads to significantly higher certified robust accuracy compared to interval-bound propagation (IBP) based training. We achieve certified robust accuracy 69.79%, 57.78% and 53.19% while IBP-based methods achieve 44.96%, 44.74% and 44.66% on 2,3 and 4 layer networks respectively on the MNIST-dataset.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0e81fd03-6e80-426e-8e16-ba5fd5cec465Cited by top-tier papers28
- Curse of Dimensionality on Randomized Smoothing for Certifiable RobustnessAounon Kumar, Alexander Levine, Tom Goldstein, Soheil FeiziICML 2020 · 102 citations
- Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100Sahil Singla, Surbhi Singla, Soheil FeiziICLR 2022 · 77 citations
- TRS: Transferability Reduced Ensemble via Promoting Gradient Diversity and Model SmoothnessZhuolin Yang, Linyi Li, Xiaojun Xu, Shiliang Zuo et al.NeurIPS 2021 · 76 citations
- Skew Orthogonal ConvolutionsSahil Singla, Soheil FeiziICML 2021 · 76 citations
- Adversarial Robustness Through the Lens of CausalityYonggang Zhang, Mingming Gong, Tongliang Liu, Gang Niu et al.ICLR 2022 · 65 citations
Builds on4
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha et al.S&P 2016 · 3,275 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov et al.S&P 2018 · 987 citations
- Towards Stable and Efficient Training of Verifiably Robust Neural NetworksHuan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal et al.ICLR 2020 · 384 citations
Related papers
- Compositional Curvature Bounds for Deep Neural NetworksTaha Entesari, Sina Sharifi, Mahyar FazlyabICML 2024 · 2 citations
- Scalable Verified Training for Provably Robust Image ClassificationSven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel et al.ICCV 2019 · 196 citations
- Tightening Robustness Verification of Convolutional Neural Networks with Fine-Grained Linear ApproximationYiting Wu, Min ZhangAAAI 2021 · 23 citations
- Understanding Certified Training with Interval Bound PropagationYuhao Mao, Mark Niklas Müller, Marc Fischer, Martin T. VechevICLR 2024 · 26 citations
- Fantastic Four: Differentiable and Efficient Bounds on Singular Values of Convolution LayersSahil Singla, Soheil FeiziICLR 2021 · 2 citations
