Defending Against Adversarial Attacks via Neural Dynamic System
Xiyuan Li, Xin Zou, Weiwei Liu
Abstract
Although deep neural networks (DNN) have achieved great success, their applications in safety-critical areas are hindered due to their vulnerability to adversarial attacks. Some recent works have accordingly proposed to enhance the robustness of DNN from a dynamic system perspective. Following this line of inquiry, and inspired by the asymptotic stability of the general nonautonomous dynamical system, we propose to make each clean instance be the asymptotically stable equilibrium points of a slowly time-varying system in order to defend against adversarial attacks. We present a theoretical guarantee that if a clean instance is an asymptotically stable equilibrium point and the adversarial instance is in the neighborhood of this point, the asymptotic stability will reduce the adversarial noise to bring the adversarial instance close to the clean instance. Motivated by our theoretical results, we go on to propose a nonautonomous neural ordinary differential equation (ASODE) and place constraints on its corresponding linear time-variant system to make all clean instances act as its asymptotically stable equilibrium points. Our analysis suggests that the constraints can be converted to regularizers in implementation. The experimental results show that ASODE improves robustness against adversarial attacks and outperforms the state-of-the-art methods.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4671c0c6-1ad5-4f4f-a33f-1ad8a7353349Cited by top-tier papers12
- Better Diffusion Models Further Improve Adversarial TrainingZekai Wang, Tianyu Pang, Chao Du, Min Lin et al.ICML 2023 · 300 citations
- Adversarial Self-Training Improves Robustness and Generalization for Gradual Domain AdaptationLianghe Shi, Weiwei LiuNeurIPS 2023 · 34 citations
- A Theory of Transfer-Based Black-Box Attacks: Explanation and ImplicationsYanbo Chen, Weiwei LiuNeurIPS 2023 · 22 citations
- On the Adversarial Robustness of Out-of-distribution Generalization ModelsXin Zou, Weiwei LiuNeurIPS 2023 · 10 citations
- A Closer Look at Curriculum Adversarial Training: From an Online PerspectiveLianghe Shi, Weiwei LiuAAAI 2024 · 7 citations
Builds on4
- On Robustness of Neural Ordinary Differential EquationsHanshu Yan, Jiawei Du, Vincent Y. F. Tan, Jiashi FengICLR 2020 · 161 citations
- Implicit Euler Skip Connections: Enhancing Adversarial Robustness via Numerical StabilityMingjie Li, Lingshen He, Zhouchen LinICML 2020 · 36 citations
- Robustness Verification for Contrastive LearningZekai Wang, Weiwei LiuICML 2022 · 17 citations
- Robust Design of Deep Neural Networks Against Adversarial Attacks Based on Lyapunov TheoryArash Rahnama, André T. Nguyen, Edward RaffCVPR 2020
Related papers
- Stable Neural ODE with Lyapunov-Stable Equilibrium Points for Defending Against Adversarial AttacksQiyu Kang, Yang Song, Qinxu Ding, Wee Peng TayNeurIPS 2021 · 130 citations
- Lyapunov-Stable Deep Equilibrium ModelsHaoyu Chu, Shikui Wei, Ting Liu, Yao Zhao et al.AAAI 2024 · 10 citations
- Interpolation between Residual and Non-Residual NetworksZonghan Yang, Yang Liu, Chenglong Bao, Zuoqiang ShiICML 2020 · 13 citations
- Adversarially Robust Out-of-Distribution Detection Using Lyapunov-Stabilized EmbeddingsHossein Mirzaei, Mackenzie W. MathisICLR 2025
- Robust Stable Spiking Neural NetworksJianhao Ding, Zhiyu Pan, Yujia Liu, Zhaofei Yu et al.ICML 2024 · 16 citations
