arXiv:2411.01644cs.LG2024-11NeurIPS被引 3

提出知识连续性,实现跨域鲁棒性认证。

Achieving Domain-Independent Certified Robustness via Knowledge Continuity

  • 基于损失函数与中间特征空间定义新鲁棒性度量
  • 认证结果不依赖输入模态、范数和分布
  • 可用于模型正则化与脆弱模块定位

我们提出知识连续性,一种受利普希茨连续性启发的新定义,旨在对神经网络在不同输入域(如视觉的连续域与语言的离散域)上的鲁棒性进行认证。现有方法多局限于连续域,且依赖范数与分布的保证。而我们的定义仅依赖损失函数和神经网络学习的中间度量空间,其边界与域模态、范数及分布无关。我们进一步证明,模型表达能力与知识连续性并不矛盾,因此通过最大化知识连续性实现鲁棒性不会理论性损害推理性能。最后,为补充理论结果,我们展示了知识连续性的多个应用:正则化、认证算法,并验证其可用于定位神经网络中的脆弱组件。

原文摘要 · Abstract (English)

We present knowledge continuity, a novel definition inspired by Lipschitz continuity which aims to certify the robustness of neural networks across input domains (such as continuous and discrete domains in vision and language, respectively). Most existing approaches that seek to certify robustness, especially Lipschitz continuity, lie within the continuous domain with norm and distribution-dependent guarantees. In contrast, our proposed definition yields certification guarantees that depend only on the loss function and the intermediate learned metric spaces of the neural network. These bounds are independent of domain modality, norms, and distribution. We further demonstrate that the expressiveness of a model class is not at odds with its knowledge continuity. This implies that achieving robustness by maximizing knowledge continuity should not theoretically hinder inferential performance. Finally, to complement our theoretical results, we present several applications of knowledge continuity such as regularization, a certification algorithm, and show that knowledge continuity can be used to localize vulnerable components of a neural network.

鲁棒性神经网络认证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。