Rethinking Lipschitz Neural Networks and Certified Robustness: A Boolean Function Perspective
Bohang Zhang, Du Jiang, Di He, Liwei Wang
摘要
Designing neural networks with bounded Lipschitz constant is a promising way to obtain certifiably robust classifiers against adversarial examples. However, the relevant progress for the important perturbation setting is rather limited, and a principled understanding of how to design expressive Lipschitz networks is still lacking. In this paper, we bridge the gap by studying certified robustness from a novel perspective of representing Boolean functions. We derive two fundamental impossibility results that hold for any standard Lipschitz network: one for robust classification on finite datasets, and the other for Lipschitz function approximation. These results identify that networks built upon norm-bounded affine layers and Lipschitz activations intrinsically lose expressive power even in the two-dimensional case, and shed light on how recently proposed Lipschitz networks (e.g., GroupSort and -distance nets) bypass these impossibilities by leveraging order statistic functions. Finally, based on these insights, we develop a unified Lipschitz network that generalizes prior works, and design a practical version that can be efficiently trained (making certified robust training free). Extensive experiments show that our approach is scalable, efficient, and consistently yields better certified robustness across multiple datasets and perturbation radii than prior Lipschitz networks. Our code is available at https://github.com/zbh2047/SortNet.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper25
- Temperature Balancing, Layer-wise Weight Analysis, and Neural Network TrainingYefan Zhou, Tianyu Pang, Keqin Liu, Charles H. Martin 等NeurIPS 2023 · 被引用 29 次
- Expressive Losses for Verified Robustness via Convex CombinationsAlessandro De Palma, Rudy Bunel, Krishnamurthy (Dj) Dvijotham, M. Pawan Kumar 等ICLR 2024 · 被引用 27 次
- Banana: Banach Fixed-Point Network for Pointcloud Segmentation with Inter-Part EquivarianceCongyue Deng, Jiahui Lei, William B. Shen, Kostas Daniilidis 等NeurIPS 2023 · 被引用 26 次
- Eliminating Catastrophic Overfitting Via Abnormal Adversarial Examples RegularizationRunqi Lin, Chaojian Yu, Tongliang LiuNeurIPS 2023 · 被引用 25 次
- Efficient Bound of Lipschitz Constant for Convolutional Layers by Gram IterationBlaise Delattre, Quentin Barthélemy, Alexandre Araujo, Alexandre AllauzenICML 2023 · 被引用 20 次
它引用的顶会 Paper22
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov 等S&P 2018 · 被引用 987 次
- Automatic Perturbation Analysis for Scalable Certified Robustness and BeyondKaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang 等NeurIPS 2020 · 被引用 415 次
- Towards Stable and Efficient Training of Verifiably Robust Neural NetworksHuan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal 等ICLR 2020 · 被引用 384 次
- Beta-CROWN: Efficient Bound Propagation with Per-neuron Split Constraints for Neural Network Robustness VerificationShiqi Wang, Huan Zhang, Kaidi Xu, Xue Lin 等NeurIPS 2021 · 被引用 359 次
相关 Paper
- Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100Sahil Singla, Surbhi Singla, Soheil FeiziICLR 2022 · 被引用 77 次
- Towards Certifying L-infinity Robustness using Neural Networks with L-inf-dist NeuronsBohang Zhang, Tianle Cai, Zhou Lu, Di He 等ICML 2021 · 被引用 62 次
- Enhancing Certified Robustness via Block Reflector Orthogonal Layers and Logit Annealing LossBo-Han Lai, Pin-Han Huang, Bo-Han Kung, Shang-Tse ChenICML 2025
- Boosting the Certified Robustness of L-infinity Distance NetsBohang Zhang, Du Jiang, Di He, Liwei WangICLR 2022 · 被引用 36 次
- Novel Quadratic Constraints for Extending LipSDP beyond Slope-Restricted ActivationsPatricia Pauli, Aaron J. Havens, Alexandre Araujo, Siddharth Garg 等ICLR 2024 · 被引用 7 次
