用代数几何方法验证多项式神经网络的鲁棒性,发现其决策边界更简单。
Robustness Verification of Polynomial Neural Networks
- 通过欧氏距离度量复杂度,分析决策边界的代数特性。
- 实测闪电自注意力模块的决策边界复杂度低于同类通用三次曲面。
- 提出符号消去与同伦连续法,实现精确鲁棒性认证,适合理论研究者。
我们通过度量代数几何研究神经网络的鲁棒性验证。对于多项式神经网络,验证鲁棒半径等价于计算到代数决策边界的距离。采用欧氏距离(ED)度作为该问题复杂性的内在度量,分析相关ED判别式,并引入参数判别式以识别使ED度降低的参数值。推导了若干网络结构的ED度公式,并刻画了无限宽极限下的实临界点期望数量。开发了符号消去方法以计算这些量,并使用同伦连续方法实现精确鲁棒性认证。最后,在闪电自注意力模块上的实验表明,其决策边界相较于同维通用三次超曲面具有更低的严格ED度。
原文摘要 · Abstract (English)
We study robustness verification of neural networks via metric algebraic geometry. For polynomial neural networks, certifying a robustness radius amounts to computing the distance to the algebraic decision boundary. We use the Euclidean distance (ED) degree as an intrinsic measure of the complexity of this problem, analyze the associated ED discriminant, and introduce a parameter discriminant that detects parameter values at which the ED degree drops. We derive formulas for the ED degree for several network architectures and characterize the expected number of real critical points in the infinite-width limit. We develop symbolic elimination methods to compute these quantities and homotopy-continuation methods for exact robustness certification. Finally, experiments on lightning self-attention modules reveal decision boundaries with strictly smaller ED degree than generic cubic hypersurfaces of the same ambient dimension.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。