Large Norms of CNN Layers Do Not Hurt Adversarial Robustness
Youwei Liang, Dong Huang
摘要
Since the Lipschitz properties of convolutional neural networks (CNNs) are widely considered to be related to adversarial robustness, we theoretically characterize the L-1 norm and L-infinity norm of 2D multi-channel convolutional layers and provide efficient methods to compute the exact L-1 norm and L-infinity norm. Based on our theorem, we propose a novel regularization method termed norm decay, which can effectively reduce the norms of convolutional layers and fully-connected layers. Experiments show that norm-regularization methods, including norm decay, weight decay, and singular value clipping, can improve generalization of CNNs. However, they can slightly hurt adversarial robustness. Observing this unexpected phenomenon, we compute the norms of layers in the CNNs trained with three different adversarial training frameworks and surprisingly find that adversarially robust CNNs have comparable or even larger layer norms than their non-adversarially robust counterparts. Furthermore, we prove that under a mild assumption, adversarially robust classifiers can be achieved using neural networks, and an adversarially robust neural network can have an arbitrarily large Lipschitz constant. For this reason, enforcing small norms on CNN layers may be neither necessary nor effective in achieving adversarial robustness. The code is available at https://github.com/youweiliang/norm_robustness.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Fantastic Robustness Measures: The Secrets of Robust GeneralizationHoki Kim, Jinseong Park, Yujin Choi, Jaewook LeeNeurIPS 2023 · 被引用 13 次
- When Flatness Does (Not) Guarantee Adversarial RobustnessNils Philipp Walter, Linara Adilova, Jilles Vreeken, Michael KampICLR 2026 · 被引用 7 次
- A Black-Box Evaluation Framework for Semantic Robustness in Bird's Eye View DetectionFu Wang, Yanghao Zhang, Xiangyu Yin, Guangliang Cheng 等AAAI 2025 · 被引用 1 次
它引用的顶会 Paper5
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Improving Adversarial Robustness Requires Revisiting Misclassified ExamplesYisen Wang, Difan Zou, Jinfeng Yi, James Bailey 等ICLR 2020 · 被引用 829 次
- A Closer Look at Accuracy vs. RobustnessYao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov 等NeurIPS 2020 · 被引用 336 次
- Boosting Adversarial Training with Hypersphere EmbeddingTianyu Pang, Xiao Yang, Yinpeng Dong, Taufik Xu 等NeurIPS 2020 · 被引用 170 次
- Designing Network Design SpacesIlija Radosavovic, Raj Prateek Kosaraju, Ross B. Girshick, Kaiming He 等CVPR 2020
相关 Paper
- Improved techniques for deterministic l2 robustnessSahil Singla, Soheil FeiziNeurIPS 2022 · 被引用 13 次
- On Lipschitz Regularization of Convolutional Layers using Toeplitz Matrix TheoryAlexandre Araujo, Benjamin Négrevergne, Yann Chevaleyre, Jamal AtifAAAI 2021 · 被引用 31 次
- Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100Sahil Singla, Surbhi Singla, Soheil FeiziICLR 2022 · 被引用 77 次
- Defending against Universal Adversarial Patches by Clipping Feature NormsCheng Yu, Jiansheng Chen, Youze Xue, Yuyang Liu 等ICCV 2021 · 被引用 34 次
- Skew Orthogonal ConvolutionsSahil Singla, Soheil FeiziICML 2021 · 被引用 76 次
