Robust Design of Deep Neural Networks Against Adversarial Attacks Based on Lyapunov Theory
Arash Rahnama, André T. Nguyen, Edward Raff
摘要
Deep neural networks (DNNs) are vulnerable to subtle adversarial perturbations applied to the input. These adversarial perturbations, though imperceptible, can easily mislead the DNN. In this work, we take a control theoretic approach to the problem of robustness in DNNs. We treat each individual layer of the DNN as a nonlinear system and use Lyapunov theory to prove stability and robustness locally. We then proceed to prove stability and robustness globally for the entire DNN. We develop empirically tight bounds on the response of the output layer, or any hidden layer, to adversarial perturbations added to the input, or to any preceding hidden layer. We show how the spectral norm of the weight matrix for an individual layer relates to Lyapunov properties of that layer, and consequently to the local and global stability and robustness of the DNN. Our results give new insights into how spectral norm regularization can mitigate the adversarial effects. Finally, we evaluate the power of our approach on a variety of data sets and network architectures and against some of the well-known adversarial attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Defending Against Adversarial Attacks via Neural Dynamic SystemXiyuan Li, Xin Zou, Weiwei LiuNeurIPS 2022 · 被引用 23 次
- Learning Diverse-Structured Networks for Adversarial RobustnessXuefeng Du, Jingfeng Zhang, Bo Han, Tongliang Liu 等ICML 2021 · 被引用 22 次
- Towards Robustness of Deep Neural Networks via RegularizationYao Li, Martin Renqiang Min, Thomas C. M. Lee, Wenchao Yu 等ICCV 2021 · 被引用 8 次
- Random Spiking Neural Networks are Stable and Spectrally SimpleErnesto Araya, Massimiliano Datres, Gitta KutyniokICLR 2026 · 被引用 1 次
- Understanding and Improving Adversarial Robustness of Neural Probabilistic CircuitsWeixin Chen, Han ZhaoNeurIPS 2025 · 被引用 1 次
它引用的顶会 Paper1
相关 Paper
- Stable Neural ODE with Lyapunov-Stable Equilibrium Points for Defending Against Adversarial AttacksQiyu Kang, Yang Song, Qinxu Ding, Wee Peng TayNeurIPS 2021 · 被引用 130 次
- Lyapunov-Stable Deep Equilibrium ModelsHaoyu Chu, Shikui Wei, Ting Liu, Yao Zhao 等AAAI 2024 · 被引用 10 次
- PAC-Bayesian Spectrally-Normalized Bounds for Adversarially Robust GeneralizationJiancong Xiao, Ruoyu Sun, Zhi-Quan LuoNeurIPS 2023 · 被引用 14 次
- Adversarial Training is a Form of Data-dependent Operator Norm RegularizationKevin Roth, Yannic Kilcher, Thomas HofmannNeurIPS 2020 · 被引用 61 次
- Fantastic Four: Differentiable and Efficient Bounds on Singular Values of Convolution LayersSahil Singla, Soheil FeiziICLR 2021 · 被引用 2 次
