arXiv:2502.14833cs.LG2025-02被引 7

提出概率鲁棒性框架,让深度学习模型更可靠地应对随机扰动。

Probabilistic Robustness in Deep Learning: A Concise yet Comprehensive Guide

  • 重构对抗训练的极小极大优化框架,提升模型对随机扰动的鲁棒性。
  • 首次将概率鲁棒性验证证据融入系统级安全保障,打通模型到系统的落地链路。
  • 适合关注模型可靠性、系统安全性的研究人员与工程团队。

深度学习在诸多安全关键场景中展现出巨大潜力,但确保其鲁棒性仍是核心挑战。尽管对抗鲁棒性在最坏情况下的研究已较为深入,概率鲁棒性(PR)通过量化随机扰动下的故障概率,提供了更贴近实际的视角。本文系统综述了PR的正式定义、评估与增强方法,提出一种专为提升PR设计的重构极小极大优化框架。进一步探讨将PR验证证据整合至系统级安全保证中的路径,解决从模型层鲁棒性向系统级声明转化的难题。最后指出若干开放问题:如何统一评估PR方法、拓展至生成式AI任务、建立严谨的方法论与案例研究以支持系统级集成。

原文摘要 · Abstract (English)

Deep learning (DL) has demonstrated significant potential across various safety-critical applications, yet ensuring its robustness remains a key challenge. While adversarial robustness has been extensively studied in worst-case scenarios, probabilistic robustness (PR) offers a more practical perspective by quantifying the likelihood of failures under stochastic perturbations. This paper provides a concise yet comprehensive overview of PR, covering its formal definitions, evaluation and enhancement methods. We introduce a reformulated ''min-max'' optimisation framework for adversarial training specifically designed to improve PR. Furthermore, we explore the integration of PR verification evidence into system-level safety assurance, addressing challenges in translating DL model-level robustness to system-level claims. Finally, we highlight open research questions, including benchmarking PR evaluation methods, extending PR to generative AI tasks, and developing rigorous methodologies and case studies for system-level integration.

概率鲁棒性深度学习系统安全对抗训练

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。