Theory of Minimal Weight Perturbations in Deep Networks and its Applications for Low-Rank Activated Backdoor Attacks
Bethan Evans, Jared Tanner
摘要
The minimal norm weight perturbations of DNNs required to achieve a specified change in output are derived and the factors determining its size are discussed. These single-layer exact formulae are contrasted with more generic multi-layer Lipschitz constant based robustness guarantees; both are observed to be of the same order which indicates similar efficacy in their guarantees. These results are applied to precision-modification-activated backdoor attacks, establishing provable compression thresholds below which such attacks cannot succeed, and show empirically that low-rank compression can reliably activate latent backdoors while preserving full-precision accuracy. These expressions reveal how back-propagated margins govern layer-wise sensitivity and provide certifiable guarantees on the smallest parameter updates consistent with a desired output shift.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper4
- Sharpness-aware Minimization for Efficiently Improving GeneralizationPierre Foret, Ariel Kleiner, Hossein Mobahi, Behnam NeyshaburICLR 2021 · 被引用 1,861 次
- CPT: Efficient Deep Neural Network Training via Cyclic PrecisionYonggan Fu, Han Guo, Meng Li, Xin Yang 等ICLR 2021 · 被引用 36 次
- Towards Certificated Model Robustness Against Weight PerturbationsTsui-Wei Weng, Pu Zhao, Sijia Liu, Pin-Yu Chen 等AAAI 2020 · 被引用 33 次
- Small Singular Values Matter: A Random Matrix Analysis of Transformer ModelsMax Staats, Matthias Thamm, Bernd RosenowNeurIPS 2025 · 被引用 21 次
相关 Paper
- Fooling a Complete Neural Network VerifierDániel Zombori, Balázs Bánhelyi, Tibor Csendes, István Megyeri 等ICLR 2021 · 被引用 21 次
- Nearest is Not Dearest: Towards Practical Defense Against Quantization-Conditioned Backdoor AttacksBoheng Li, Yishuo Cai, Haowei Li, Feng Xue 等CVPR 2024
- Direct Parameterization of Lipschitz-Bounded Deep NetworksRuigang Wang, Ian R. ManchesterICML 2023 · 被引用 66 次
- Smoothed Geometry for Robust AttributionZifan Wang, Haofan Wang, Shakul Ramkumar, Piotr Mardziel 等NeurIPS 2020 · 被引用 67 次
- Logit-Margin Repulsion for Backdoor DefenseZhiguo Yang, Dongsheng Xu, Ruizhi Zhong, Jiacheng Pi 等CVPR 2026
