A Closer Look at the Adversarial Robustness of Deep Equilibrium Models
Zonghan Yang, Tianyu Pang, Yang Liu
摘要
Deep equilibrium models (DEQs) refrain from the traditional layer-stacking paradigm and turn to find the fixed point of a single layer. DEQs have achieved promising performance on different applications with featured memory efficiency. At the same time, the adversarial vulnerability of DEQs raises concerns. Several works propose to certify robustness for monotone DEQs. However, limited efforts are devoted to studying empirical robustness for general DEQs. To this end, we observe that an adversarially trained DEQ requires more forward steps to arrive at the equilibrium state, or even violates its fixed-point structure. Besides, the forward and backward tracks of DEQs are misaligned due to the black-box solvers. These facts cause gradient obfuscation when applying the ready-made attacks to evaluate or adversarially train DEQs. Given this, we develop approaches to estimate the intermediate gradients of DEQs and integrate them into the attacking pipelines. Our approaches facilitate fully white-box evaluations and lead to effective adversarial defense for DEQs. Extensive experiments on CIFAR-10 validate the adversarial robustness of DEQs competitive with deep networks of similar sizes.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- Better Diffusion Models Further Improve Adversarial TrainingZekai Wang, Tianyu Pang, Chao Du, Min Lin 等ICML 2023 · 被引用 300 次
- Lyapunov-Stable Deep Equilibrium ModelsHaoyu Chu, Shikui Wei, Ting Liu, Yao Zhao 等AAAI 2024 · 被引用 10 次
- Understanding Representation of Deep Equilibrium Models from Neural Collapse PerspectiveHaixiang Sun, Ye ShiNeurIPS 2024 · 被引用 4 次
- Subhomogeneous Deep Equilibrium ModelsPietro Sittoni, Francesco TudiscoICML 2024 · 被引用 3 次
- Improving Adversarial Robustness of Deep Equilibrium Models with Explicit Regulations Along the Neural DynamicsZonghan Yang, Peng Li, Tianyu Pang, Yang LiuICML 2023 · 被引用 3 次
它引用的顶会 Paper16
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Fast is better than free: Revisiting adversarial trainingEric Wong, Leslie Rice, J. Zico KolterICLR 2020 · 被引用 1,352 次
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
- Bag of Tricks for Adversarial TrainingTianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su 等ICLR 2021 · 被引用 298 次
- Training Graph Neural Networks with 1000 LayersGuohao Li, Matthias Müller, Bernard Ghanem, Vladlen KoltunICML 2021 · 被引用 294 次
相关 Paper
- Stabilizing Equilibrium Models by Jacobian RegularizationShaojie Bai, Vladlen Koltun, J. Zico KolterICML 2021 · 被引用 80 次
- Certified Robustness for Deep Equilibrium Models via Interval Bound PropagationColin Wei, J. Zico KolterICLR 2022 · 被引用 22 次
- Certified Robustness for Deep Equilibrium Models via Serialized Random SmoothingWeizhi Gao, Zhichao Hou, Han Xu, Xiaorui LiuNeurIPS 2024 · 被引用 2 次
- CerDEQ: Certifiable Deep Equilibrium ModelMingjie Li, Yisen Wang, Zhouchen LinICML 2022 · 被引用 13 次
- Joint inference and input optimization in equilibrium networksSwaminathan Gurumurthy, Shaojie Bai, Zachary Manchester, J. Zico KolterNeurIPS 2021 · 被引用 22 次
