On Certifying Non-uniform Bound against Adversarial Attacks

03/15/2019
by   Chen Liu, et al.
8

This work studies the robustness certification problem of neural network models, which aims to find certified adversary-free regions as large as possible around data points. In contrast to the existing approaches that seek regions bounded uniformly along all input features, we consider non-uniform bounds and use it to study the decision boundary of neural network models. We formulate our target as an optimization problem with nonlinear constraints. Then, a framework applicable for general feedforward neural networks is proposed to bound the output logits so that the relaxed problem can be solved by the augmented Lagrangian method. Our experiments show the non-uniform bounds have larger volumes than uniform ones. Compared with normal models, the robust models have even larger non-uniform bounds and better interpretability. Further, the geometric similarity of the non-uniform bounds gives a quantitative, data-agnostic metric of input features' robustness.

READ FULL TEXT

page 7

page 15

research
10/24/2018

Minsum k-Sink Problem on Path Networks

We consider the problem of locating a set of k sinks on a path network w...
research
10/31/2017

5G Ultra-dense networks with non-uniform Distributed Users

User distribution in ultra-dense networks (UDNs) plays a crucial role in...
research
02/24/2021

Adversarial Robustness with Non-uniform Perturbations

Robustness of machine learning models is critical for security related a...
research
05/30/2023

NUNO: A General Framework for Learning Parametric PDEs with Non-Uniform Data

The neural operator has emerged as a powerful tool in learning mappings ...
research
10/06/2022

Structure Representation Network and Uncertainty Feedback Learning for Dense Non-Uniform Fog Removal

Few existing image defogging or dehazing methods consider dense and non-...
research
01/24/2017

By chance is not enough: Preserving relative density through non uniform sampling

Dealing with visualizations containing large data set is a challenging i...
research
09/30/2019

Non-uniform Berry-Esseen Bound by Unbounded Exchangeable Pair Approach

Since Stein presented his ideas in the seminal paper s1, there have been...

Please sign up or login with your details

Forgot password? Click here to reset