Direct Parameterization of Lipschitz-Bounded Deep Networks
Ruigang Wang, Ian R. Manchester
Abstract
This paper introduces a new parameterization of deep neural networks (both fully-connected and convolutional) with guaranteed Lipschitz bounds, i.e. limited sensitivity to input perturbations. The Lipschitz guarantees are equivalent to the tightest-known bounds based on certification via a semidefinite program (SDP). We provide a ``direct'' parameterization, i.e., a smooth mapping from onto the set of weights satisfying the SDP-based bound. Moreover, our parameterization is complete, i.e. a neural network satisfies the SDP bound if and only if it can be represented via our parameterization. This enables training using standard gradient methods, without any inner approximation or computationally intensive tasks (e.g. projections or barrier terms) for the SDP constraint. The new parameterization can equivalently be thought of as either a new layer type (the sandwich layer), or a novel parameterization of standard feedforward networks with parameter sharing between neighbouring layers. A comprehensive set of experiments on image classification shows that sandwich layers outperform previous approaches on both empirical and certified robust accuracy. Code is available at https://github.com/acfr/LBDN.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d5759efb-2105-4058-9e52-7945673a8a18Cited by top-tier papers24
- Some Fundamental Aspects about Lipschitz Continuity of Neural NetworksGrigory Khromov, Sidak Pal SinghICLR 2024 · 29 citations
- Certified Robustness via Dynamic Margin Maximization and Improved Lipschitz RegularizationMahyar Fazlyab, Taha Entesari, Aniket Roy, Rama ChellappaNeurIPS 2023 · 26 citations
- On the Scalability and Memory Efficiency of Semidefinite Programs for Lipschitz Constant Estimation of Neural NetworksZi Wang, Bin Hu, Aaron J. Havens, Alexandre Araujo et al.ICLR 2024 · 20 citations
- ECLipsE: Efficient Compositional Lipschitz Constant Estimation for Deep Neural NetworksYuezhu Xu, S. SivaranjaniNeurIPS 2024 · 19 citations
- Exploiting Connections between Lipschitz Structures for Certifiably Robust Deep Equilibrium ModelsAaron J. Havens, Alexandre Araujo, Siddharth Garg, Farshad Khorrami et al.NeurIPS 2023 · 15 citations
Builds on14
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Deep Double Descent: Where Bigger Models and More Data HurtPreetum Nakkiran, Gal Kaplun, Yamini Bansal, Tristan Yang et al.ICLR 2020 · 1,108 citations
- A Universal Law of Robustness via IsoperimetrySébastien Bubeck, Mark SellkeNeurIPS 2021 · 260 citations
- Monotone operator equilibrium networksEzra Winston, J. Zico KolterNeurIPS 2020 · 177 citations
- Optimal Regularization can Mitigate Double DescentPreetum Nakkiran, Prayaag Venkat, Sham M. Kakade, Tengyu MaICLR 2021 · 148 citations
Related papers
- A Unified Algebraic Perspective on Lipschitz Neural NetworksAlexandre Araujo, Aaron J. Havens, Blaise Delattre, Alexandre Allauzen et al.ICLR 2023 · 1 citation
- 1-Lipschitz Layers Compared: Memory, Speed, and Certifiable RobustnessBernd Prach, Fabio Brau, Giorgio C. Buttazzo, Christoph H. LampertCVPR 2024 · 4 citations
- Semialgebraic Optimization for Lipschitz Constants of ReLU NetworksTong Chen, Jean B. Lasserre, Victor Magron, Edouard PauwelsNeurIPS 2020 · 51 citations
- LOT: Layer-wise Orthogonal Training on Improving l2 Certified RobustnessXiaojun Xu, Linyi Li, Bo LiNeurIPS 2022 · 42 citations
- Regularized Training and Tight Certification for Randomized Smoothed Classifier with Provable RobustnessHuijie Feng, Chunpeng Wu, Guoyang Chen, Weifeng Zhang et al.AAAI 2020 · 13 citations
