A Closer Look at the Adversarial Robustness of Deep Equilibrium Models
Zonghan Yang, Tianyu Pang, Yang Liu
Abstract
Deep equilibrium models (DEQs) refrain from the traditional layer-stacking paradigm and turn to find the fixed point of a single layer. DEQs have achieved promising performance on different applications with featured memory efficiency. At the same time, the adversarial vulnerability of DEQs raises concerns. Several works propose to certify robustness for monotone DEQs. However, limited efforts are devoted to studying empirical robustness for general DEQs. To this end, we observe that an adversarially trained DEQ requires more forward steps to arrive at the equilibrium state, or even violates its fixed-point structure. Besides, the forward and backward tracks of DEQs are misaligned due to the black-box solvers. These facts cause gradient obfuscation when applying the ready-made attacks to evaluate or adversarially train DEQs. Given this, we develop approaches to estimate the intermediate gradients of DEQs and integrate them into the attacking pipelines. Our approaches facilitate fully white-box evaluations and lead to effective adversarial defense for DEQs. Extensive experiments on CIFAR-10 validate the adversarial robustness of DEQs competitive with deep networks of similar sizes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 592a4d83-cf31-4d86-bb54-86989e76ee7fCited by top-tier papers10
- Better Diffusion Models Further Improve Adversarial TrainingZekai Wang, Tianyu Pang, Chao Du, Min Lin et al.ICML 2023 · 300 citations
- Lyapunov-Stable Deep Equilibrium ModelsHaoyu Chu, Shikui Wei, Ting Liu, Yao Zhao et al.AAAI 2024 · 10 citations
- Understanding Representation of Deep Equilibrium Models from Neural Collapse PerspectiveHaixiang Sun, Ye ShiNeurIPS 2024 · 4 citations
- Subhomogeneous Deep Equilibrium ModelsPietro Sittoni, Francesco TudiscoICML 2024 · 3 citations
- Improving Adversarial Robustness of Deep Equilibrium Models with Explicit Regulations Along the Neural DynamicsZonghan Yang, Peng Li, Tianyu Pang, Yang LiuICML 2023 · 3 citations
Builds on16
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 1,352 citations
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- Bag of Tricks for Adversarial TrainingTianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su et al.ICLR 2021 · 298 citations
- Training Graph Neural Networks with 1000 LayersGuohao Li, Matthias Müller, Bernard Ghanem, Vladlen KoltunICML 2021 · 294 citations
Related papers
- Stabilizing Equilibrium Models by Jacobian RegularizationShaojie Bai, Vladlen Koltun, J. Zico KolterICML 2021 · 80 citations
- Certified Robustness for Deep Equilibrium Models via Interval Bound PropagationColin Wei, J. Zico KolterICLR 2022 · 22 citations
- Certified Robustness for Deep Equilibrium Models via Serialized Random SmoothingWeizhi Gao, Zhichao Hou, Han Xu, Xiaorui LiuNeurIPS 2024 · 2 citations
- CerDEQ: Certifiable Deep Equilibrium ModelMingjie Li, Yisen Wang, Zhouchen LinICML 2022 · 13 citations
- Joint inference and input optimization in equilibrium networksSwaminathan Gurumurthy, Shaojie Bai, Zachary Manchester, J. Zico KolterNeurIPS 2021 · 22 citations
