On the Certified Robustness for Ensemble Models and Beyond
Zhuolin Yang, Linyi Li, Xiaojun Xu, Bhavya Kailkhura, Tao Xie, Bo Li
摘要
Recent studies show that deep neural networks (DNN) are vulnerable to adversarial examples, which aim to mislead DNNs by adding perturbations with small magnitude. To defend against such attacks, both empirical and theoretical defense approaches have been extensively studied for a single ML model. In this work, we aim to analyze and provide the certified robustness for ensemble ML models, together with the sufficient and necessary conditions of robustness for different ensemble protocols. Although ensemble models are shown more robust than a single model empirically; surprisingly, we find that in terms of the certified robustness the standard ensemble models only achieve marginal improvement compared to a single model. Thus, to explore the conditions that guarantee to provide certifiably robust ensemble ML models, we first prove that diversified gradient and large confidence margin are sufficient and necessary conditions for certifiably robust ensemble models under the model-smoothness assumption. We then provide the bounded model-smoothness analysis based on the proposed Ensemble-before-Smoothing strategy. We also prove that an ensemble model can always achieve higher certified robustness than a single base model under mild conditions. Inspired by the theoretical findings, we propose the lightweight Diversity Regularized Training (DRT) to train certifiably robust ensemble ML models. Extensive experiments show that our DRT enhanced ensembles can consistently achieve higher certified robustness than existing single and ensemble ML models, demonstrating the state-of-the-art certified L 2 -robustness on MNIST, CIFAR-10, and ImageNet datasets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper25
- LOT: Layer-wise Orthogonal Training on Improving l2 Certified RobustnessXiaojun Xu, Linyi Li, Bo LiNeurIPS 2022 · 被引用 42 次
- Boosting the Certified Robustness of L-infinity Distance NetsBohang Zhang, Du Jiang, Di He, Liwei WangICLR 2022 · 被引用 36 次
- Quantifying and Enhancing Multi-modal Robustness with Modality PreferenceZequn Yang, Yake Wei, Ce Liang, Di HuICLR 2024 · 被引用 27 次
- Building Robust Ensembles via Margin BoostingDinghuai Zhang, Hongyang Zhang, Aaron C. Courville, Yoshua Bengio 等ICML 2022 · 被引用 18 次
- (Certified!!) Adversarial Robustness for Free!Nicholas Carlini, Florian Tramèr, Krishnamurthy (Dj) Dvijotham, Leslie Rice 等ICLR 2023 · 被引用 17 次
它引用的顶会 Paper19
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Distillation as a Defense to Adversarial Perturbations Against Deep Neural NetworksNicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha 等S&P 2016 · 被引用 3,275 次
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 被引用 1,026 次
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu 等S&P 2019 · 被引用 1,022 次
- Why Do Adversarial Attacks Transfer? Explaining Transferability of Evasion and Poisoning AttacksAmbra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski 等USENIX Security 2019 · 被引用 466 次
相关 Paper
- TRS: Transferability Reduced Ensemble via Promoting Gradient Diversity and Model SmoothnessZhuolin Yang, Linyi Li, Xiaojun Xu, Shiliang Zuo 等NeurIPS 2021 · 被引用 76 次
- Regularized Training and Tight Certification for Randomized Smoothed Classifier with Provable RobustnessHuijie Feng, Chunpeng Wu, Guoyang Chen, Weifeng Zhang 等AAAI 2020 · 被引用 13 次
- Exploiting Joint Robustness to Adversarial PerturbationsAli Dabouei, Sobhan Soleymani, Fariborz Taherkhani, Jeremy M. Dawson 等CVPR 2020
- Self-ensemble Adversarial Training for Improved RobustnessHongjun Wang, Yisen WangICLR 2022 · 被引用 61 次
- Adversarial Defence by Diversified Simultaneous Training of Deep EnsemblesBo Huang, Zhiwei Ke, Yi Wang, Wei Wang 等AAAI 2021 · 被引用 20 次
