Boosting Certified ℓ_∞ Robustness with EMA Method and Ensemble Model

07/01/2021
by   Binghui Li, et al.
0

The neural network with 1-Lipschitz property based on ℓ_∞-dist neuron has a theoretical guarantee in certified ℓ_∞ robustness. However, due to the inherent difficulties in the training of the network, the certified accuracy of previous work is limited. In this paper, we propose two approaches to deal with these difficuties. Aiming at the characteristics of the training process based on ℓ_∞-norm neural network, we introduce the EMA method to improve the training process. Considering the randomness of the training algorithm, we propose an ensemble method based on trained base models that have the 1-Lipschitz property and gain significant improvement in the small parameter network. Moreover, we give the theoretical analysis of the ensemble method based on the 1-Lipschitz property on the certified robustness, which ensures the effectiveness and stability of the algorithm. Our code is available at https://github.com/Theia-4869/EMA-and-Ensemble-Lip-Networks.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/28/2018

RecurJac: An Efficient Recursive Algorithm for Bounding Jacobian Matrix of Neural Networks and Its Applications

The Jacobian matrix (or the gradient for single-output networks) is dire...
research
10/13/2022

Efficiently Computing Local Lipschitz Constants of Neural Networks via Bound Propagation

Lipschitz constants are connected to many properties of neural networks,...
research
11/15/2022

Improved techniques for deterministic l2 robustness

Training convolutional neural networks (CNNs) with a strict 1-Lipschitz ...
research
10/13/2021

Boosting the Certified Robustness of L-infinity Distance Nets

Recently, Zhang et al. (2021) developed a new neural network architectur...
research
05/25/2023

Efficient Bound of Lipschitz Constant for Convolutional Layers by Gram Iteration

Since the control of the Lipschitz constant has a great impact on the tr...
research
06/15/2020

Inner Ensemble Nets

We introduce Inner Ensemble Networks (IENs) which reduce the variance wi...
research
01/06/2020

Express Wavenet – a low parameter optical neural network with random shift wavelet pattern

Express Wavenet is an improved optical diffractive neural network. At ea...

Please sign up or login with your details

Forgot password? Click here to reset