用拓扑表示提升模型鲁棒性,可验证对抗样本下的安全性。
Certifying Robustness via Topological Representations
- 从拓扑图学习几何特征,保证输出稳定变化
- 在ORBIT5K数据集上实现ε-鲁棒性认证
- 适合关注模型安全与拓扑分析的研究者
我们提出一种神经网络架构,能够从持久性图(persistence diagrams)中学习数据的判别性几何表示,这类图是拓扑数据分析中的常见描述符。所学表示具有李普希茨稳定性,且其常数可控制。在对抗学习中,这种稳定性可用于对数据集中样本进行ε-鲁棒性认证,我们在代表离散动力系统轨道的ORBIT5K数据集上进行了验证。
原文摘要 · Abstract (English)
We propose a neural network architecture that can learn discriminative geometric representations of data from persistence diagrams, common descriptors of Topological Data Analysis. The learned representations enjoy Lipschitz stability with a controllable Lipschitz constant. In adversarial learning, this stability can be used to certify $ε$-robustness for samples in a dataset, which we demonstrate on the ORBIT5K dataset representing the orbits of a discrete dynamical system.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。