Adversarial Examples in Multi-Layer Random ReLU Networks
Peter L. Bartlett, Sébastien Bubeck, Yeshwanth Cherapanamjeri
摘要
We consider the phenomenon of adversarial examples in ReLU networks with independent gaussian parameters. For networks of constant depth and with a large range of widths (for instance, it suffices if the width of each layer is polynomial in that of any other layer), small perturbations of input vectors lead to large changes of outputs. This generalizes results of Daniely and Schacham (2020) for networks of rapidly decreasing width and of Bubeck et al ( 2021 ) for two-layer networks. The proof shows that adversarial examples arise in these networks because the functions that they compute are very close to linear. Bottleneck layers in the network play a key role: the minimal width up to some point in the network determines scales and sensitivities of mappings computed up to that point. The main result is for networks with constant depth, but we also show that some constraint on depth is necessary for a result of this kind, because there are suitably deep networks that, with constant probability, compute a function that is close to constant.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper15
- Cross-Entropy Loss Functions: Theoretical Analysis and ApplicationsAnqi Mao, Mehryar Mohri, Yutao ZhongICML 2023 · 被引用 790 次
- H-Consistency Bounds for Surrogate Loss MinimizersPranjal Awasthi, Anqi Mao, Mehryar Mohri, Yutao ZhongICML 2022 · 被引用 50 次
- Gradient Methods Provably Converge to Non-Robust NetworksGal Vardi, Gilad Yehudai, Ohad ShamirNeurIPS 2022 · 被引用 32 次
- On the Existence of The Adversarial Bayes ClassifierPranjal Awasthi, Natalie Frank, Mehryar MohriNeurIPS 2021 · 被引用 29 次
- The Double-Edged Sword of Implicit Bias: Generalization vs. Robustness in ReLU NetworksSpencer Frei, Gal Vardi, Peter L. Bartlett, Nati SrebroNeurIPS 2023 · 被引用 25 次
它引用的顶会 Paper1
相关 Paper
- Most ReLU Networks Suffer from Adversarial PerturbationsAmit Daniely, Hadas ShachamNeurIPS 2020 · 被引用 17 次
- A single gradient step finds adversarial examples on random two-layers neural networksSébastien Bubeck, Yeshwanth Cherapanamjeri, Gauthier Gidel, Remi Tachet des CombesNeurIPS 2021 · 被引用 31 次
- Adversarial Robustness Guarantees for Random Deep Neural NetworksGiacomo De Palma, Bobak Toussi Kiani, Seth LloydICML 2021 · 被引用 10 次
- Functional vs. parametric equivalence of ReLU networksMary Phuong, Christoph H. LampertICLR 2020 · 被引用 53 次
- Contrasting Adversarial Perturbations: The Space of Harmless PerturbationsLu Chen, Shaofeng Li, Benhao Huang, Fan Yang 等AAAI 2025 · 被引用 1 次
