LOT: Layer-wise Orthogonal Training on Improving l2 Certified Robustness
Xiaojun Xu, Linyi Li, Bo Li
Abstract
Recent studies show that training deep neural networks (DNNs) with Lipschitz constraints are able to enhance adversarial robustness and other model properties such as stability. In this paper, we propose a layer-wise orthogonal training method (LOT) to effectively train 1-Lipschitz convolution layers via parametrizing an orthogonal matrix with an unconstrained matrix. We then efficiently compute the inverse square root of a convolution kernel by transforming the input domain to the Fourier frequency domain. On the other hand, as existing works show that semisupervised training helps improve empirical robustness, we aim to bridge the gap and prove that semi-supervised learning also improves the certified robustness of Lipschitz-bounded models. We conduct comprehensive evaluations for LOT under different settings. We show that LOT significantly outperforms baselines regarding deterministic 2 certified robustness, and scales to deeper neural networks. Under the supervised scenario, we improve the state-of-the-art certified robustness for all architectures (e.g. from 59.04% to 63.50% on CIFAR-10 and from 32.57% to 34.59% on CIFAR-100 at radius ρ = 36/255 for 40-layer networks). With semisupervised learning over unlabelled data, we are able to improve state-of-the-art certified robustness on CIFAR-10 at ρ = 108/255 from 36.04% to 42.39%. In addition, LOT consistently outperforms baselines on different model architectures with only 1/3 evaluation time. 36th Conference on Neural Information Processing Systems (NeurIPS 2022).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a1f3fbbe-c4bc-4365-ab08-1c2c5d13db91Cited by top-tier papers26
- Direct Parameterization of Lipschitz-Bounded Deep NetworksRuigang Wang, Ian R. ManchesterICML 2023 · 66 citations
- Expressive Losses for Verified Robustness via Convex CombinationsAlessandro De Palma, Rudy Bunel, Krishnamurthy (Dj) Dvijotham, M. Pawan Kumar et al.ICLR 2024 · 27 citations
- Unlocking Deterministic Robustness Certification on ImageNetKai Hu, Andy Zou, Zifan Wang, Klas Leino et al.NeurIPS 2023 · 18 citations
- PROSAC: Provably Safe Certification for Machine Learning Models under Adversarial AttacksChen Feng, Ziquan Liu, Zhuo Zhi, Ilija Bogunovic et al.AAAI 2025 · 15 citations
- DP-SGD Without Clipping: The Lipschitz Neural Network WayLouis Béthune, Thomas Massena, Thibaut Boissin, Aurélien Bellet et al.ICLR 2024 · 13 citations
Builds on16
- Theoretical Analysis of Self-Training with Deep Networks on Unlabeled DataColin Wei, Kendrick Shen, Yining Chen, Tengyu MaICLR 2021 · 261 citations
- Lipschitz constant estimation of Neural Networks via sparse polynomial optimizationFabian Latorre, Paul Rolland, Volkan CevherICLR 2020 · 154 citations
- Orthogonalizing Convolutional Layers with the Cayley TransformAsher Trockman, J. Zico KolterICLR 2021 · 137 citations
- Feature Purification: How Adversarial Training Performs Robust Deep LearningZeyuan Allen-Zhu, Yuanzhi LiFOCS 2021 · 83 citations
- Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100Sahil Singla, Surbhi Singla, Soheil FeiziICLR 2022 · 77 citations
Related papers
- Improved techniques for deterministic l2 robustnessSahil Singla, Soheil FeiziNeurIPS 2022 · 13 citations
- Skew Orthogonal ConvolutionsSahil Singla, Soheil FeiziICML 2021 · 76 citations
- Adversarial Training and Provable Defenses: Bridging the GapMislav Balunovic, Martin T. VechevICLR 2020 · 186 citations
- Convolutional Normalization: Improving Deep Convolutional Network Robustness and TrainingSheng Liu, Xiao Li, Yuexiang Zhai, Chong You et al.NeurIPS 2021 · 30 citations
- On Lipschitz Regularization of Convolutional Layers using Toeplitz Matrix TheoryAlexandre Araujo, Benjamin Négrevergne, Yann Chevaleyre, Jamal AtifAAAI 2021 · 31 citations
