arXiv:2510.00083cs.CVcs.LG2025-10

通过剪枝提升神经网络语义鲁棒性,更高效且更可信。

Enhancing Certifiable Semantic Robustness via Robust Pruning of Deep Neural Networks

  • 基于无偏平滑神经元指标筛选关键神经元,实现精准剪枝。
  • 在真实亮度/对比度扰动下,认证鲁棒性优于现有方法。
  • 适合需要高可信度的视觉与机器人系统应用。

深度神经网络在视觉与机器人领域广泛应用,但其对亮度、对比度等语义变换扰动的鲁棒性验证至关重要。当前认证训练与鲁棒性认证方法受过参数化限制,导致认证紧致性差且扩展性不足。本文分析了层与神经元对输入扰动的稳定性与方差,提出一个基础指标——无偏平滑神经元(USN),可有效指示可认证鲁棒性。基于此,我们设计一种新剪枝方法,移除低USN神经元,保留高USN神经元,以维持模型表达能力的同时避免过参数化。为进一步优化剪枝分布,引入基于Wasserstein距离的损失函数,使剪枝后的神经元在层间更集中。在具有挑战性的鲁棒关键点检测任务上进行大量实验,涵盖真实世界的亮度与对比度扰动,结果表明,该方法在认证鲁棒性与计算效率方面均显著优于基线方法。

原文摘要 · Abstract (English)

Deep neural networks have been widely adopted in many vision and robotics applications with visual inputs. It is essential to verify its robustness against semantic transformation perturbations, such as brightness and contrast. However, current certified training and robustness certification methods face the challenge of over-parameterization, which hinders the tightness and scalability due to the over-complicated neural networks. To this end, we first analyze stability and variance of layers and neurons against input perturbation, showing that certifiable robustness can be indicated by a fundamental Unbiased and Smooth Neuron metric (USN). Based on USN, we introduce a novel neural network pruning method that removes neurons with low USN and retains those with high USN, thereby preserving model expressiveness without over-parameterization. To further enhance this pruning process, we propose a new Wasserstein distance loss to ensure that pruned neurons are more concentrated across layers. We validate our approach through extensive experiments on the challenging robust keypoint detection task, which involves realistic brightness and contrast perturbations, demonstrating that our method achieves superior robustness certification performance and efficiency compared to baselines.

神经网络剪枝鲁棒性认证视觉任务

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。