Improved techniques for deterministic l2 robustness
Sahil Singla, Soheil Feizi
Abstract
Training convolutional neural networks (CNNs) with a strict 1-Lipschitz constraint under the norm is useful for adversarial robustness, interpretable gradients and stable training. 1-Lipschitz CNNs are usually designed by enforcing each layer to have an orthogonal Jacobian matrix (for all inputs) to prevent the gradients from vanishing during backpropagation. However, their performance often significantly lags behind that of heuristic methods to enforce Lipschitz constraints where the resulting CNN is not provably 1-Lipschitz. In this work, we reduce this gap by introducing (a) a procedure to certify robustness of 1-Lipschitz CNNs by replacing the last linear layer with a 1-hidden layer MLP that significantly improves their performance for both standard and provably robust accuracy, (b) a method to significantly reduce the training time per epoch for Skew Orthogonal Convolution (SOC) layers (>30% reduction for deeper networks) and (c) a class of pooling layers using the mathematical property that the distance of an input to a manifold is 1-Lipschitz. Using these methods, we significantly advance the state-of-the-art for standard and provable robust accuracies on CIFAR-10 (gains of +1.79% and +3.82%) and similarly on CIFAR-100 (+3.78% and +4.75%) across all networks. Code is available at https://github.com/singlasahil14/improved_l2_robustness.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers9
- Expressive Losses for Verified Robustness via Convex CombinationsAlessandro De Palma, Rudy Bunel, Krishnamurthy (Dj) Dvijotham, M. Pawan Kumar et al.ICLR 2024 · 27 citations
- Exploiting Connections between Lipschitz Structures for Certifiably Robust Deep Equilibrium ModelsAaron J. Havens, Alexandre Araujo, Siddharth Garg, Farshad Khorrami et al.NeurIPS 2023 · 15 citations
- DP-SGD Without Clipping: The Lipschitz Neural Network WayLouis Béthune, Thomas Massena, Thibaut Boissin, Aurélien Bellet et al.ICLR 2024 · 13 citations
- Robust One-Class Classification with Signed Distance Function using 1-Lipschitz Neural NetworksLouis Béthune, Paul Novello, Guillaume Coiffier, Thibaut Boissin et al.ICML 2023 · 12 citations
- 1-Lipschitz Layers Compared: Memory, Speed, and Certifiable RobustnessBernd Prach, Fabio Brau, Giorgio C. Buttazzo, Christoph H. LampertCVPR 2024 · 4 citations
Builds on22
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- Beta-CROWN: Efficient Bound Propagation with Per-neuron Split Constraints for Neural Network Robustness VerificationShiqi Wang, Huan Zhang, Kaidi Xu, Xue Lin et al.NeurIPS 2021 · 359 citations
- Denoised Smoothing: A Provable Defense for Pretrained ClassifiersHadi Salman, Mingjie Sun, Greg Yang, Ashish Kapoor et al.NeurIPS 2020 · 191 citations
- Globally-Robust Neural NetworksKlas Leino, Zifan Wang, Matt FredriksonICML 2021 · 150 citations
- Orthogonalizing Convolutional Layers with the Cayley TransformAsher Trockman, J. Zico KolterICLR 2021 · 137 citations
Related papers
- Skew Orthogonal ConvolutionsSahil Singla, Soheil FeiziICML 2021 · 76 citations
- Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100Sahil Singla, Surbhi Singla, Soheil FeiziICLR 2022 · 77 citations
- Constructing Orthogonal Convolutions in an Explicit MannerTan Yu, Jun Li, Yunfeng Cai, Ping LiICLR 2022 · 19 citations
- Large Norms of CNN Layers Do Not Hurt Adversarial RobustnessYouwei Liang, Dong HuangAAAI 2021 · 13 citations
- LOT: Layer-wise Orthogonal Training on Improving l2 Certified RobustnessXiaojun Xu, Linyi Li, Bo LiNeurIPS 2022 · 42 citations
