让压缩后的模型依然具备可证明的抗干扰能力。
Compression Aware Certified Training
- 训练时同步考虑压缩与鲁棒性,避免二者互斥
- 压缩后仍保持高认证准确率,适用于剪枝和量化
- 适合对安全性和效率都有要求的部署场景
在安全性要求高且资源受限的环境中部署深度神经网络,需兼顾效率与鲁棒性。现有方法将压缩与可认证鲁棒性视为独立目标,导致效率或安全性的妥协。我们提出CACTUS(Compression Aware Certified Training Using network Sets)框架,统一训练阶段的压缩与认证鲁棒性目标。该框架训练的模型在压缩后仍能保持高认证准确率。我们在剪枝和量化两种压缩方式上应用CACTUS,证明其能有效训练出既高效又具备高准确率与可证明鲁棒性的模型。在多种数据集和输入规格下,CACTUS在剪枝与量化任务中均达到当前最优的准确率与认证性能。
原文摘要 · Abstract (English)
Deep neural networks deployed in safety-critical, resource-constrained environments must balance efficiency and robustness. Existing methods treat compression and certified robustness as separate goals, compromising either efficiency or safety. We propose CACTUS (Compression Aware Certified Training Using network Sets), a general framework for unifying these objectives during training. CACTUS models maintain high certified accuracy even when compressed. We apply CACTUS for both pruning and quantization and show that it effectively trains models which can be efficiently compressed while maintaining high accuracy and certifiable robustness. CACTUS achieves state-of-the-art accuracy and certified performance for both pruning and quantization on a variety of datasets and input specifications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。