Lune

ICML2021顶会

Towards Certifying L-infinity Robustness using Neural Networks with L-inf-dist Neurons

Bohang Zhang, Tianle Cai, Zhou Lu, Di He, Liwei Wang

2021年份
62被引次数
27顶会引用

摘要

It is well-known that standard neural networks, even with a high classification accuracy, are vulnerable to small ℓ∞\ell_\infty-norm bounded adversarial perturbations. Although many attempts have been made, most previous works either can only provide empirical verification of the defense to a particular attack method, or can only develop a certified guarantee of the model robustness in limited scenarios. In this paper, we seek for a new approach to develop a theoretically principled neural network that inherently resists ℓ∞\ell_\infty perturbations. In particular, we design a novel neuron that uses ℓ∞\ell_\infty-distance as its basic operation (which we call ℓ∞\ell_\infty-dist neuron), and show that any neural network constructed with ℓ∞\ell_\infty-dist neurons (called ℓ∞\ell_{\infty}-dist net) is naturally a 1-Lipschitz function with respect to ℓ∞\ell_\infty-norm. This directly provides a rigorous guarantee of the certified robustness based on the margin of prediction outputs. We then prove that such networks have enough expressive power to approximate any 1-Lipschitz function with robust generalization guarantee. We further provide a holistic training strategy that can greatly alleviate optimization difficulties. Experimental results show that using ℓ∞\ell_{\infty}-dist nets as basic building blocks, we consistently achieve state-of-the-art performance on commonly used datasets: 93.09% certified accuracy on MNIST (ϵ=0.3\epsilon=0.3), 35.42% on CIFAR-10 (ϵ=8/255\epsilon=8/255) and 16.31% on TinyImageNet (ϵ=1/255\epsilon=1/255).

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext b5364fa3-e38f-45fd-b288-0541a5fc5a3c

引用它的顶会 Paper27

问问它们各自怎么用它

它引用的顶会 Paper12

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖