通过敏感性分析提升深度神经网络的稳定性与鲁棒性。
On the Stability of Neural Networks in Deep Learning
- 以输入和参数扰动为视角,研究模型对微小变化的响应机制。
- 提出Lipschitz约束层与曲率正则化,显著改善训练稳定性和抗噪能力。
- 适合关注模型鲁棒性、安全性与可解释性的研究人员参考。
深度学习在众多任务中取得显著成功,但其模型常面临不稳定与脆弱问题:输入微小变化可能导致预测大幅波动,优化过程也易受尖锐损失曲面阻碍。本文从敏感性分析出发,统一考察输入与参数扰动下的网络响应。研究证明,通过构造Lipschitz网络可有效限制输入扰动的敏感性,从而提升泛化能力、对抗鲁棒性与训练稳定性。同时,引入基于损失函数曲率的正则化方法,促进更平滑的优化景观,降低对参数变化的敏感度。此外,探索了随机平滑这一概率性增强决策边界鲁棒性的方法。三者结合形成统一框架,实现对稳定性挑战的系统性应对。论文贡献包括理论分析、高效的谱范数计算方法、新型Lipschitz约束层及改进的认证流程。
原文摘要 · Abstract (English)
Deep learning has achieved remarkable success across a wide range of tasks, but its models often suffer from instability and vulnerability: small changes to the input may drastically affect predictions, while optimization can be hindered by sharp loss landscapes. This thesis addresses these issues through the unifying perspective of sensitivity analysis, which examines how neural networks respond to perturbations at both the input and parameter levels. We study Lipschitz networks as a principled way to constrain sensitivity to input perturbations, thereby improving generalization, adversarial robustness, and training stability. To complement this architectural approach, we introduce regularization techniques based on the curvature of the loss function, promoting smoother optimization landscapes and reducing sensitivity to parameter variations. Randomized smoothing is also explored as a probabilistic method for enhancing robustness at decision boundaries. By combining these perspectives, we develop a unified framework where Lipschitz continuity, randomized smoothing, and curvature regularization interact to address fundamental challenges in stability. The thesis contributes both theoretical analysis and practical methodologies, including efficient spectral norm computation, novel Lipschitz-constrained layers, and improved certification procedures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。