首个可扩展至十亿参数的确定性鲁棒模型,突破了传统认证方法的规模瓶颈。
LipNeXt: Scaling up Lipschitz-based Certified Robustness to Billion-parameter Models
- 采用正交流形优化与空间移位模块,实现无卷积、无约束的1-Lipschitz设计
- 在ImageNet上支持1-2B参数模型,ε=1时认证准确率提升达+8%
- 适合追求高效、确定性鲁棒性的大模型研究与部署场景
基于Lipschitz的认证提供高效且确定的鲁棒性保障,但长期受限于模型规模、训练效率和ImageNet性能。本文提出首个无约束、无卷积的1-Lipschitz架构LipNeXt,核心包含:(1) 直接在正交流形上更新参数的流形优化;(2) 通过空间移位模块建模空间模式。全网络采用正交投影、空间移位、1-Lipschitz的β-Abs非线性及$ L_2 $空间池化,实现紧密的Lipschitz控制并支持强表达力特征融合。在CIFAR-10/100与Tiny-ImageNet上达到最优的干净与认证鲁棒准确率;在ImageNet上可扩展至1-2B参数模型,在ε=1时认证准确率较先前模型最高提升+8%,同时保持高效的低精度训练稳定性。结果表明,基于Lipschitz的认证可受益于现代模型扩展趋势,而不牺牲确定性与效率。
原文摘要 · Abstract (English)
Lipschitz-based certification offers efficient, deterministic robustness guarantees but has struggled to scale in model size, training efficiency, and ImageNet performance. We introduce \emph{LipNeXt}, the first \emph{constraint-free} and \emph{convolution-free} 1-Lipschitz architecture for certified robustness. LipNeXt is built using two techniques: (1) a manifold optimization procedure that updates parameters directly on the orthogonal manifold and (2) a \emph{Spatial Shift Module} to model spatial pattern without convolutions. The full network uses orthogonal projections, spatial shifts, a simple 1-Lipschitz $β$-Abs nonlinearity, and $L_2$ spatial pooling to maintain tight Lipschitz control while enabling expressive feature mixing. Across CIFAR-10/100 and Tiny-ImageNet, LipNeXt achieves state-of-the-art clean and certified robust accuracy (CRA), and on ImageNet it scales to 1-2B large models, improving CRA over prior Lipschitz models (e.g., up to $+8\%$ at $\varepsilon{=}1$) while retaining efficient, stable low-precision training. These results demonstrate that Lipschitz-based certification can benefit from modern scaling trends without sacrificing determinism or efficiency.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。