Training Robust Ensembles Requires Rethinking Lipschitz Continuity
Ali Ebrahimpour Boroojeny, Hari Sundaram, Varun Chandrasekaran
摘要
Transferability of adversarial examples is a well-known property that endangers all classification models, even those that are only accessible through black-box queries. Prior work has shown that an ensemble of models is more resilient to transferability: the probability that an adversarial example is effective against most models of the ensemble is low. Thus, most ongoing research focuses on improving ensemble diversity. Another line of prior work has shown that Lipschitz continuity of the models can make models more robust since it limits how a model's output changes with small input perturbations. In this paper, we study the effect of Lipschitz continuity on transferability rates. We show that although a lower Lipschitz constant increases the robustness of a single model, it is not as beneficial in training robust ensembles as it increases the transferability rate of adversarial examples across models in the ensemble. Therefore, we introduce LOTOS, a new training paradigm for ensembles, which counteracts this adverse effect. It does so by promoting orthogonality among the top-k sub-spaces of the transformations of the corresponding affine layers of any pair of models in the ensemble. We theoretically show that k does not need to be large for convolutional layers, which makes the computational overhead negligible. Through various experiments, we show LOTOS increases the robust accuracy of ensembles of ResNet-18 models by 6 percentage points (p.p) against black-box attacks on CIFAR-10. It is also capable of combining with the robustness of prior state-of-the-art methods for training robust ensembles to enhance their robust accuracy by 10.7 p.p. The code is publicly available at https://github.com/Ali-E/LOTOS .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper14
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- DVERGE: Diversifying Vulnerabilities for Enhanced Robust Generation of EnsemblesHuanrui Yang, Jingyang Zhang, Hongliang Dong, Nathan Inkawhich 等NeurIPS 2020 · 被引用 144 次
- Orthogonalizing Convolutional Layers with the Cayley TransformAsher Trockman, J. Zico KolterICLR 2021 · 被引用 137 次
- Rethinking Model Ensemble in Transfer-based Adversarial AttacksHuanran Chen, Yichi Zhang, Yinpeng Dong, Xiao Yang 等ICLR 2024 · 被引用 112 次
- Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100Sahil Singla, Surbhi Singla, Soheil FeiziICLR 2022 · 被引用 77 次
相关 Paper
- TRS: Transferability Reduced Ensemble via Promoting Gradient Diversity and Model SmoothnessZhuolin Yang, Linyi Li, Xiaojun Xu, Shiliang Zuo 等NeurIPS 2021 · 被引用 76 次
- To Tackle Adversarial Transferability: A Novel Ensemble Training Method with Fourier TransformationWanlin Zhang, Weichen Lin, Ruomin Huang, Shihong Song 等ICLR 2025
- Adversarial Defence by Diversified Simultaneous Training of Deep EnsemblesBo Huang, Zhiwei Ke, Yi Wang, Wei Wang 等AAAI 2021 · 被引用 20 次
- Improving Ensemble Robustness by Collaboratively Promoting and Demoting Adversarial RobustnessTuan-Anh Bui, Trung Le, He Zhao, Paul Montague 等AAAI 2021 · 被引用 13 次
- Certifying Ensembles: A General Certification Theory with S-LipschitznessAleksandar Petrov, Francisco Eiras, Amartya Sanyal, Philip H. S. Torr 等ICML 2023 · 被引用 2 次
