Boosting the Certified Robustness of L-infinity Distance Nets
Bohang Zhang, Du Jiang, Di He, Liwei Wang
Abstract
Recently, Zhang et al. (2021) developed a new neural network architecture based on -distance functions, which naturally possesses certified robustness by its construction. Despite the novel design and theoretical foundation, so far the model only achieved comparable performance to conventional networks. In this paper, we make the following two contributions: We demonstrate that -distance nets enjoy a fundamental advantage in certified robustness over conventional networks (under typical certification approaches); With an improved training process we are able to significantly boost the certified accuracy of -distance nets. Our training approach largely alleviates the optimization problem that arose in the previous training scheme, in particular, the unexpected large Lipschitz constant due to the use of a crucial trick called -relaxation. The core of our training approach is a novel objective function that combines scaled cross-entropy loss and clipped hinge loss with a decaying mixing coefficient. Experiments show that using the proposed training strategy, the certified accuracy of -distance net can be dramatically improved from 33.30% to 40.06% on CIFAR-10 (), meanwhile outperforming other approaches in this area by a large margin. Our results clearly demonstrate the effectiveness and potential of -distance net for certified robustness. Codes are available at https://github.com/zbh2047/L_inf-dist-net-v2.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 67c8dd7b-0539-40de-b97e-71acbd07f5e8Cited by top-tier papers17
- Rethinking Lipschitz Neural Networks and Certified Robustness: A Boolean Function PerspectiveBohang Zhang, Du Jiang, Di He, Liwei WangNeurIPS 2022 · 88 citations
- Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100Sahil Singla, Surbhi Singla, Soheil FeiziICLR 2022 · 77 citations
- Efficiently Computing Local Lipschitz Constants of Neural Networks via Bound PropagationZhouxing Shi, Yihan Wang, Huan Zhang, J. Zico Kolter et al.NeurIPS 2022 · 73 citations
- On the Certified Robustness for Ensemble Models and BeyondZhuolin Yang, Linyi Li, Xiaojun Xu, Bhavya Kailkhura et al.ICLR 2022 · 57 citations
- Expressive Losses for Verified Robustness via Convex CombinationsAlessandro De Palma, Rudy Bunel, Krishnamurthy (Dj) Dvijotham, M. Pawan Kumar et al.ICLR 2024 · 27 citations
Builds on25
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey et al.ICLR 2020 · 829 citations
- Automatic Perturbation Analysis for Scalable Certified Robustness and BeyondKaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang et al.NeurIPS 2020 · 415 citations
Related papers
- Towards Certifying L-infinity Robustness using Neural Networks with L-inf-dist NeuronsBohang Zhang, Tianle Cai, Zhou Lu, Di He et al.ICML 2021 · 62 citations
- Certify or Predict: Boosting Certified Robustness with Compositional ArchitecturesMark Niklas Müller, Mislav Balunovic, Martin T. VechevICLR 2021 · 14 citations
- Adversarial Training and Provable Robustness: A Tale of Two ObjectivesJiameng Fan, Wenchao LiAAAI 2021 · 23 citations
- On the Scalability of Certified Adversarial Robustness with Generated DataThomas Altstidl, David Dobre, Arthur Kosmala, Bjoern M. Eskofier et al.NeurIPS 2024 · 10 citations
- Fast Training of Provably Robust Neural Networks by SinglePropAkhilan Boopathy, Lily Weng, Sijia Liu, Pin-Yu Chen et al.AAAI 2021 · 8 citations
