arXiv:2509.17898eess.SYcs.LG2025-09

为循环神经网络提供可证明的抗扰动能力,通过凸松弛求解利普希茨常数。

Lipschitz-Based Robustness Certification for Recurrent Neural Networks via Convex Relaxation

  • 将RNN层间交互建模为凸问题,用半定规划计算利普希茨上界。
  • 在多水箱系统上验证,序列长度增加时仍保持紧致且可认证的边界。
  • 揭示初始化误差对控制应用的重要影响,适合模型预测控制场景。

在安全关键控制应用中,对循环神经网络(RNN)进行对抗性扰动下的鲁棒性认证日益重要。为此,我们提出RNN-SDP方法,将RNN层间相互作用建模为凸问题,并通过半定规划(SDP)计算利普希茨常数的可认证上界。我们还探索了引入已知输入约束以进一步收紧利普希茨边界的方法。RNN-SDP在合成多水箱系统上进行了评估,其上界与经验估计对比。尽管引入输入约束仅带来小幅改进,但该方法在序列长度增加时仍能产生合理紧致且可认证的边界。结果也凸显了初始化误差的潜在影响,这对于频繁重初始化的场景(如模型预测控制,MPC)尤为重要。

原文摘要 · Abstract (English)

Robustness certification against bounded input noise or adversarial perturbations is increasingly important for deployment recurrent neural networks (RNNs) in safety-critical control applications. To address this challenge, we present RNN-SDP, a relaxation based method that models the RNN's layer interactions as a convex problem and computes a certified upper bound on the Lipschitz constant via semidefinite programming (SDP). We also explore an extension that incorporates known input constraints to further tighten the resulting Lipschitz bounds. RNN-SDP is evaluated on a synthetic multi-tank system, with upper bounds compared to empirical estimates. While incorporating input constraints yields only modest improvements, the general method produces reasonably tight and certifiable bounds, even as sequence length increases. The results also underscore the often underestimated impact of initialization errors, an important consideration for applications where models are frequently re-initialized, such as model predictive control (MPC).

RNN鲁棒性凸优化控制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。