arXiv:2512.05915cs.LGcs.SY2025-12

提出可证明的 Lipschitz 网络构造方法,提升模型鲁棒性与可信性

LDLT $\mathcal{L}$-Lipschitz Network: Generalized Deep End-To-End Lipschitz Network Construction

  • 基于 LMI 与 LDL^T 分解,构建可验证 Lipschitz 常数的深层网络
  • 在 121 个 UCI 数据集上比 SLL 层提升 3%-13% 准确率
  • 适用于对抗鲁棒性、可认证训练与控制系统设计

深度残差网络(ResNets)在计算机视觉任务中表现卓越,得益于其保持深层梯度流动的能力。同时,控制神经网络的 Lipschitz 常数已成为增强对抗鲁棒性和网络可认证性的关键研究方向。本文提出一种严格的 $/mathcal{L}$-Lipschitz 深层残差网络通用设计方法,采用线性矩阵不等式(LMI)框架。首先将 ResNet 重构为循环三对角 LMI,推导出保证 $/mathcal{L}$-Lipschitz 连续性的参数闭式约束;随后通过新的 LDL^T 分解方法验证 LMI 可行性,将 $/mathcal{L}$-Lipschitz 网络构造扩展至任意非线性架构。贡献包括可证明的参数化方法,用于构建 Lipschitz 约束的残差网络及其他分层结构。利用 Cholesky 分解实现高效参数化。该方法支持鲁棒网络设计,适用于对抗鲁棒性、可认证训练与控制系统。实验表明,LDL^T 形式是基于 SDP 的网络的紧松弛,保持完整表达能力,在 121 个 UCI 数据集上相比 SLL 层获得 3%-13% 的准确率提升。

原文摘要 · Abstract (English)

Deep residual networks (ResNets) have demonstrated outstanding success in computer vision tasks, attributed to their ability to maintain gradient flow through deep architectures. Simultaneously, controlling the Lipschitz constant in neural networks has emerged as an essential area of research to enhance adversarial robustness and network certifiability. This paper presents a rigorous approach to the general design of $\mathcal{L}$-Lipschitz deep residual networks using a Linear Matrix Inequality (LMI) framework. Initially, the ResNet architecture was reformulated as a cyclic tridiagonal LMI, and closed-form constraints on network parameters were derived to ensure $\mathcal{L}$-Lipschitz continuity; however, using a new $LDL^\top$ decomposition approach for certifying LMI feasibility, we extend the construction of $\mathcal{L}$-Lipchitz networks to any other nonlinear architecture. Our contributions include a provable parameterization methodology for constructing Lipschitz-constrained residual networks and other hierarchical architectures. Cholesky decomposition is also used for efficient parameterization. These findings enable robust network designs applicable to adversarial robustness, certified training, and control systems. The $LDL^\top$ formulation is shown to be a tight relaxation of the SDP-based network, maintaining full expressiveness and achieving 3\%-13\% accuracy gains over SLL Layers on 121 UCI data sets.

Lipschitz鲁棒性网络设计可认证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。