返回
Training Provably Robust Models by Polyhedral Envelope Regularization
DOI:10.1109/TNNLS.2021.3111892.png)
摘要
En 中文
Training certifiable neural networks enables us to obtain models with robustness guarantees against adversarial attacks. In this work, we introduce a framework to obtain a provable adversarial-free region in the neighborhood of the input data by a polyhedral envelope, which yields more fine-grained certified robustness than existing methods. We further introduce polyhedral envelope regularization (PER) to encourage larger adversarial-free regions and thus improve the provable robustness of the models. We demonstrate the flexibility and effectiveness of our framework on standard benchmarks; it applies to networks of different architectures and with general activation functions. Compared with state of the art, PER has negligible computational overhead; it achieves better robustness guarantees and accuracy on the clean data in various settings.
Keyword:
Robustness
Training
Predictive models
Computational modeling
Standards
Smoothing methods
Recurrent neural networks
Adversarial training
provable robustness
期刊
IF:
8.9
论文数:
7.5K
被引数:
7.2W
机构
引用论文
Welding characteristics of aluminum, copper, nickel and aluminum alloy with alumina coating using ultrasonic complex vibration welding equipments铝、铜、镍及铝合金氧化铝涂层超声复合振动焊接特性研究

