Lune

ICLR2020Top-tier venue

Provable robustness against all adversarial lpl_p-perturbations for p≥1p\geq 1

Francesco Croce, Matthias Hein

2020Year
78Citations
3Top-tier citations

Abstract

In recent years several adversarial attacks and defenses have been proposed. Often seemingly robust models turn out to be non-robust when more sophisticated attacks are used. One way out of this dilemma are provable robustness guarantees. While provably robust models for specific lpl_p-perturbation models have been developed, we show that they do not come with any guarantee against other lql_q-perturbations. We propose a new regularization scheme, MMR-Universal, for ReLU networks which enforces robustness wrt l1l_1- and l∞l_\infty-perturbations and show how that leads to the first provably robust models wrt any lpl_p-norm for p≥1p\geq 1.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 6077753e-9f08-4ab2-8723-121c46b79b88

Cited by top-tier papers3

Ask how each one uses it

Builds on1

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines