CerDEQ: Certifiable Deep Equilibrium Model
Mingjie Li, Yisen Wang, Zhouchen Lin
Abstract
Recently, certifiable robust training methods via bound propagation have been proposed for training neural networks with certifiable robustness guarantees. However, no neural architectures with regular convolution and linear layers perform better in the certifiable training than the plain CNNs, since the output bounds for the deep explicit models increase quickly as their depth increases. And such a phenomenon significantly hinders certifiable training. Meanwhile, the Deep Equilibrium Models (DEQs) are more representative and robust due to their equivalent infinite depth and controllable global Lipschitz. But no work has been proposed to explore whether DEQ can show advantages in certified training. In this work, we aim to tackle the problem of DEQ's certified training. To obtain the output bound based on the bound propagation scheme in the implicit model, we first involve the adjoint DEQ for bound approximation. Furthermore, we also use the weight orthogonalization method and other tricks specified for DEQ to stabilize the certifiable training. With our approach, we can obtain the certifiable DEQ called CerDEQ. Our CerDEQ can achieve state-of-the-art performance compared with models using regular convolution and linear layers on ℓ ∞ tasks with ϵ = 8/255: 64.72% certified error for CIFAR-10 and 94.45% certified error for Tiny ImageNet.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e24b941a-5752-45f7-942b-c36a7dd1c179Cited by top-tier papers8
- Deep Equilibrium Approaches to Diffusion ModelsAshwini Pokle, Zhengyang Geng, J. Zico KolterNeurIPS 2022 · 61 citations
- Exploiting Connections between Lipschitz Structures for Certifiably Robust Deep Equilibrium ModelsAaron J. Havens, Alexandre Araujo, Siddharth Garg, Farshad Khorrami et al.NeurIPS 2023 · 15 citations
- Lyapunov-Stable Deep Equilibrium ModelsHaoyu Chu, Shikui Wei, Ting Liu, Yao Zhao et al.AAAI 2024 · 10 citations
- Quantum Deep Equilibrium ModelsPhilipp Schleich, Marta Skreta, Lasse Bjørn Kristensen, Rodrigo A. Vargas-Hernández et al.NeurIPS 2024 · 8 citations
- Understanding Representation of Deep Equilibrium Models from Neural Collapse PerspectiveHaixiang Sun, Ye ShiNeurIPS 2024 · 4 citations
Builds on23
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Adversarial Weight Perturbation Helps Robust GeneralizationDongxian Wu, Shu-Tao Xia, Yisen WangNeurIPS 2020 · 917 citations
- Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingYulong Cao, Chaowei Xiao, Benjamin Cyr, Yimeng Zhou et al.CCS 2019 · 626 citations
- Automatic Perturbation Analysis for Scalable Certified Robustness and BeyondKaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang et al.NeurIPS 2020 · 415 citations
- Multiscale Deep Equilibrium ModelsShaojie Bai, Vladlen Koltun, J. Zico KolterNeurIPS 2020 · 272 citations
Related papers
- Certified Robustness for Deep Equilibrium Models via Interval Bound PropagationColin Wei, J. Zico KolterICLR 2022 · 22 citations
- Certified Robustness for Deep Equilibrium Models via Serialized Random SmoothingWeizhi Gao, Zhichao Hou, Han Xu, Xiaorui LiuNeurIPS 2024 · 2 citations
- Semialgebraic Representation of Monotone Deep Equilibrium Models and Applications to CertificationTong Chen, Jean B. Lasserre, Victor Magron, Edouard PauwelsNeurIPS 2021 · 25 citations
- Understanding Certified Training with Interval Bound PropagationYuhao Mao, Mark Niklas Müller, Marc Fischer, Martin T. VechevICLR 2024 · 26 citations
- Fast Certified Robust Training with Short WarmupZhouxing Shi, Yihan Wang, Huan Zhang, Jinfeng Yi et al.NeurIPS 2021 · 74 citations
