arrow
返回

Training Provably Robust Models by Polyhedral Envelope Regularization

delete2023-06-01
delete6
delete
OA
AI
C
Chen Liu *
M
Mathieu Salzmann
S
Sabine Süsstrunk
DOI:10.1109/TNNLS.2021.3111892delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Training certifiable neural networks enables us to obtain models with robustness guarantees against adversarial attacks. In this work, we introduce a framework to obtain a provable adversarial-free region in the neighborhood of the input data by a polyhedral envelope, which yields more fine-grained certified robustness than existing methods. We further introduce polyhedral envelope regularization (PER) to encourage larger adversarial-free regions and thus improve the provable robustness of the models. We demonstrate the flexibility and effectiveness of our framework on standard benchmarks; it applies to networks of different architectures and with general activation functions. Compared with state of the art, PER has negligible computational overhead; it achieves better robustness guarantees and accuracy on the clean data in various settings.
Keyword:
Robustness
Training
Predictive models
Computational modeling
Standards
Smoothing methods
Recurrent neural networks
Adversarial training
provable robustness

期刊

IEEE Transactions on Neural Networks and Learning Systems 封面图
IEEE Transactions on Neural Networks and Learning Systems
IF:
8.9
论文数:
7.5K
被引数:
7.2W

机构

S
swiss federal institutes of technology domain
学者数:
9.0W
论文数: 8.0W
被引数: 163
引用论文

引用论文

Productivity and memory for newly formed words
err2008-09-26
err0
PREAI
errEve V. Clark; Sophia R. Cohen
err分享
err收藏
Carbon−Carbon Coupling of Two Alkenyl Fragments on a Saturated Compound
err1997-06-24
err0
PREAI
errMiguel A. Esteruelas; Fenghui Liu; Enrique Oñate; Eduardo Sola; Bernd Zeier
err分享
err收藏