Lipschitz Bounds and Provably Robust Training by Laplacian Smoothing
Vishaal Krishnan, Abed AlRahman Al Makdah, Fabio Pasqualetti
Abstract
In this work we propose a graph-based learning framework to train models with provable robustness to adversarial perturbations. In contrast to regularizationbased approaches, we formulate the adversarially robust learning problem as one of loss minimization with a Lipschitz constraint, and show that the saddle point of the associated Lagrangian is characterized by a Poisson equation with weighted Laplace operator. Further, the weighting for the Laplace operator is given by the Lagrange multiplier for the Lipschitz constraint, which modulates the sensitivity of the minimizer to perturbations. We then design a provably robust training scheme using graph-based discretization of the input space and a primal-dual algorithm to converge to the Lagrangian's saddle point. Our analysis establishes a novel connection between elliptic operators with constraint-enforced weighting and adversarial learning. We also study the complementary problem of improving the robustness of minimizers with a margin on their loss, formulated as a loss-constrained minimization problem of the Lipschitz constant. We propose a technique to obtain robustified minimizers, and evaluate fundamental Lipschitz lower bounds by approaching Lipschitz constant minimization via a sequence of gradient p-norm minimization problems. Ultimately, our results show that, for a desired nominal performance, there exists a fundamental lower bound on the sensitivity to adversarial perturbations that depends only on the loss function and the data distribution, and that improvements in robustness beyond this bound can only be made at the expense of nominal performance. Our training schemes provably achieve these bounds both under constraints on performance and robustness. 1 We let µ be the underlying measure on X, since the input data is generated from µ on the support X. 2 See Supplementary Material for a proof. 3 We use ∇1 to denote the gradient of with respect to its first argument. 4 See supplementary material for a proof.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b6ffe6b7-c7d5-4d14-9cab-432a9c2a5d21Cited by top-tier papers7
- Robust Implicit Networks via Non-Euclidean ContractionsSaber Jafarpour, Alexander Davydov, Anton V. Proskurnikov, Francesco BulloNeurIPS 2021 · 59 citations
- Prompt Certified Machine Unlearning with Randomized Gradient Smoothing and QuantizationZijie Zhang, Yang Zhou, Xin Zhao, Tianshi Che et al.NeurIPS 2022 · 56 citations
- Expressive 1-Lipschitz Neural Networks for Robust Multiple Graph Learning against Adversarial AttacksXin Zhao, Zeru Zhang, Zijie Zhang, Lingfei Wu et al.ICML 2021 · 33 citations
- A Quantitative Geometric Approach to Neural-Network SmoothnessZi Wang, Gautam Prakriya, Somesh JhaNeurIPS 2022 · 20 citations
- Learning Globally Smooth Functions on ManifoldsJuan Cerviño, Luiz F. O. Chamon, Benjamin David Haeffele, René Vidal et al.ICML 2023 · 6 citations
Builds on1
Related papers
- Certified Robustness via Dynamic Margin Maximization and Improved Lipschitz RegularizationMahyar Fazlyab, Taha Entesari, Aniket Roy, Rama ChellappaNeurIPS 2023 · 26 citations
- Not All Low-Pass Filters are Robust in Graph Convolutional NetworksHeng Chang, Yu Rong, Tingyang Xu, Yatao Bian et al.NeurIPS 2021 · 65 citations
- Adversarial Robustness with Semi-Infinite Constrained LearningAlexander Robey, Luiz F. O. Chamon, George J. Pappas, Hamed Hassani et al.NeurIPS 2021 · 51 citations
- Enhancing Node-Level Adversarial Defenses by Lipschitz Regularization of Graph Neural NetworksYaning Jia, Dongmian Zou, Hongfei Wang, Hai JinKDD 2023 · 11 citations
- Adversarial Weight Perturbation Improves Generalization in Graph Neural NetworksYihan Wu, Aleksandar Bojchevski, Heng HuangAAAI 2023 · 35 citations
