首次理论分析了可解释网络在对抗攻击下的泛化能力,发现过参数化有助于提升鲁棒性。
Adversarial generalization of unfolding (model-based) networks
- 基于迭代算法构造可解释网络,用新框架估计对抗雷姆塞复杂度
- 给出紧致的对抗泛化误差界,与攻击强度严格匹配
- 实验证实过参数化能增强抗干扰能力,为高效防御提供思路
展开网络是从迭代算法中衍生出的可解释模型,融合数据结构先验知识,用于求解压缩感知等反问题,广泛应用于医学成像、密码学等关键领域,其中对抗鲁棒性至关重要。然而,现有研究对展开网络在对抗攻击下的性能缺乏理论理解。本文针对 $l_2$-范数约束攻击(由快速梯度符号法生成)下的展开网络对抗泛化问题进行研究,选取一类先进过参数化展开网络,提出新框架估算其对抗雷姆塞复杂度。基于该估计,推导出紧致的对抗泛化误差上界,且与攻击水平高度一致。据我们所知,这是首个针对展开网络对抗泛化的理论分析。我们在真实数据上开展多组实验,结果一致支持理论结论。此外,观察到该类网络的过参数化特性可被利用以提升对抗鲁棒性,为高效构建鲁棒神经网络提供了新视角。
原文摘要 · Abstract (English)
Unfolding networks are interpretable networks emerging from iterative algorithms, incorporate prior knowledge of data structure, and are designed to solve inverse problems like compressed sensing, which deals with recovering data from noisy, missing observations. Compressed sensing finds applications in critical domains, from medical imaging to cryptography, where adversarial robustness is crucial to prevent catastrophic failures. However, a solid theoretical understanding of the performance of unfolding networks in the presence of adversarial attacks is still in its infancy. In this paper, we study the adversarial generalization of unfolding networks when perturbed with $l_2$-norm constrained attacks, generated by the fast gradient sign method. Particularly, we choose a family of state-of-the-art overaparameterized unfolding networks and deploy a new framework to estimate their adversarial Rademacher complexity. Given this estimate, we provide adversarial generalization error bounds for the networks under study, which are tight with respect to the attack level. To our knowledge, this is the first theoretical analysis on the adversarial generalization of unfolding networks. We further present a series of experiments on real-world data, with results corroborating our derived theory, consistently for all data. Finally, we observe that the family's overparameterization can be exploited to promote adversarial robustness, shedding light on how to efficiently robustify neural networks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。