arXiv:2506.05434cs.LGcs.AI2025-06ICML被引 5

用李普希茨有界网络高效生成抗干扰的预测集

Efficient Robust Conformal Prediction via Lipschitz-Bounded Networks

  • 基于李普希茨有界网络设计新方法,提升鲁棒性
  • 在ImageNet上预测集更小、计算更快,优于当前最佳
  • 兼顾效率与鲁棒性,适合大规模实际部署

置信预测(CP)是一种有效的后处理方法,可为神经网络提供具有有限样本保证的预测集,从而提升模型可信度。然而,在对抗攻击下,传统CP的保证失效。为此,研究者提出了鲁棒置信预测(Robust CP),但现有方法在大规模问题中要么预测集过大,要么计算开销过高,难以实际应用。本文提出一种新方法lip-rcp,利用李普希茨有界网络精确高效地估计鲁棒预测集。当与1-Lipschitz鲁棒网络结合时,lip-rcp在ImageNet等中大规模场景下,同时实现了更小的预测集和更高的计算效率,优于现有最优方法。此外,我们还分析了普通CP在攻击下的最坏情况覆盖边界,该边界对所有攻击强度均成立。lip-rcp使该方法兼具普通CP的效率与鲁棒性保证。

原文摘要 · Abstract (English)

Conformal Prediction (CP) has proven to be an effective post-hoc method for improving the trustworthiness of neural networks by providing prediction sets with finite-sample guarantees. However, under adversarial attacks, classical conformal guarantees do not hold anymore: this problem is addressed in the field of Robust Conformal Prediction. Several methods have been proposed to provide robust CP sets with guarantees under adversarial perturbations, but, for large scale problems, these sets are either too large or the methods are too computationally demanding to be deployed in real life scenarios. In this work, we propose a new method that leverages Lipschitz-bounded networks to precisely and efficiently estimate robust CP sets. When combined with a 1-Lipschitz robust network, we demonstrate that our lip-rcp method outperforms state-of-the-art results in both the size of the robust CP sets and computational efficiency in medium and large-scale scenarios such as ImageNet. Taking a different angle, we also study vanilla CP under attack, and derive new worst-case coverage bounds of vanilla CP sets, which are valid simultaneously for all adversarial attack levels. Our lip-rcp method makes this second approach as efficient as vanilla CP while also allowing robustness guarantees.

置信预测对抗鲁棒性李普希茨约束高效推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。