Training Adversarially Robust Sparse Networks via Bayesian Connectivity Sampling
Ozan Özdenizci, Robert Legenstein
Abstract
Deep neural networks have been shown to be susceptible to adversarial attacks. This lack of adversarial robustness is even more pronounced when models are compressed in order to meet hardware limitations. Hence, if adversarial robustness is an issue, training of sparsely connected networks necessitates considering adversarially robust sparse learning. Motivated by the efficient and stable computational function of the brain in the presence of a highly dynamic synaptic connectivity structure, we propose an intrinsically sparse rewiring approach to train neural networks with state-of-the-art robust learning objectives under high sparsity. Importantly, in contrast to previously proposed pruning techniques, our approach satisfies global connectivity constraints throughout robust optimization, i.e., it does not require dense pre-training followed by pruning. Based on a Bayesian posterior sampling principle, a network rewiring process simultaneously learns the sparse connectivity structure and the robustnessaccuracy trade-off based on the adversarial learning objective. Although our networks are sparsely connected throughout the whole training process, our experimental benchmark evaluations show that their performance is superior to recently proposed robustness-aware network pruning methods which start from densely connected networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers13
- Deep Ensembling with No Overhead for either Training or Testing: The All-Round Blessings of Dynamic SparsityShiwei Liu, Tianlong Chen, Zahra Atashgahi, Xiaohan Chen et al.ICLR 2022 · 62 citations
- Sparsity Winning Twice: Better Robust Generalization from More Efficient TrainingTianlong Chen, Zhenyu Zhang, Pengjun Wang, Santosh Balachandra et al.ICLR 2022 · 54 citations
- Where to Pay Attention in Sparse Training for Feature Selection?Ghada Sokar, Zahra Atashgahi, Mykola Pechenizkiy, Decebal Constantin MocanuNeurIPS 2022 · 25 citations
- Fantastic Weights and How to Find Them: Where to Prune in Dynamic Sparse TrainingAleksandra Nowak, Bram Grooten, Decebal Constantin Mocanu, Jacek TaborNeurIPS 2023 · 23 citations
- Robust Stable Spiking Neural NetworksJianhao Ding, Zhiyu Pan, Yujia Liu, Zhaofei Yu et al.ICML 2024 · 16 citations
Builds on5
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey et al.ICLR 2020 · 829 citations
- Adversarial Robustness vs. Model Compression, or Both?Shaokai Ye, Xue Lin, Kaidi Xu, Sijia Liu et al.ICCV 2019 · 180 citations
- Adversarial Neural Pruning with Latent Vulnerability SuppressionDivyam Madaan, Jinwoo Shin, Sung Ju HwangICML 2020 · 68 citations
- What's Hidden in a Randomly Weighted Neural Network?Vivek Ramanujan, Mitchell Wortsman, Aniruddha Kembhavi, Ali Farhadi et al.CVPR 2020
Related papers
- Learning Adversarially Robust Sparse Networks via Weight ReparameterizationChenhao Li, Qiang Qiu, Zhibin Zhang, Jiafeng Guo et al.AAAI 2023 · 8 citations
- ESL-SNNs: An Evolutionary Structure Learning Strategy for Spiking Neural NetworksJiangrong Shen, Qi Xu, Jian K. Liu, Yueming Wang et al.AAAI 2023 · 64 citations
- Holistic Adversarially Robust PruningQi Zhao, Christian WressneggerICLR 2023
- HYDRA: Pruning Adversarially Robust Neural NetworksVikash Sehwag, Shiqi Wang, Prateek Mittal, Suman JanaNeurIPS 2020 · 242 citations
- Towards efficient deep spiking neural networks construction with spiking activity based pruningYaxin Li, Qi Xu, Jiangrong Shen, Hongming Xu et al.ICML 2024 · 18 citations
