通过调控神经ODE的有限时间李雅普诺夫指数,提升模型对抗鲁棒性。
Tracking Finite-Time Lyapunov Exponents to Robustify Neural ODEs
- 利用有限时间李雅普诺夫指数分析输入扰动的分离行为,揭示动态规律。
- 早期阶段抑制远离零的指数,使模型对对抗攻击更鲁棒,计算成本更低。
- 适用于需要高鲁棒性的神经ODE应用,如安全关键系统。
我们研究了连续深度神经网络框架中有限时间李雅普诺夫指数(FTLE),该指标衡量输入扰动的指数分离程度。实验表明,FTLE能有效组织输入-输出动态,提升模型可解释性,并支持不同架构的对比。我们建立了李雅普诺夫指数与对抗脆弱性之间的直接联系,提出一种新型训练算法:通过在输入动态初期抑制远离零的指数来增强鲁棒性。相比全区间正则化,该方法避免了完整的“双重”反向传播,显著降低计算开销。
原文摘要 · Abstract (English)
We investigate finite-time Lyapunov exponents (FTLEs), a measure for exponential separation of input perturbations, of deep neural networks within the framework of continuous-depth neural ODEs. We demonstrate that FTLEs are powerful organizers for input-output dynamics, allowing for better interpretability and the comparison of distinct model architectures. We establish a direct connection between Lyapunov exponents and adversarial vulnerability, and propose a novel training algorithm that improves robustness by FTLE regularization. The key idea is to suppress exponents far from zero in the early stage of the input dynamics. This approach enhances robustness and reduces computational cost compared to full-interval regularization, as it avoids a full ``double'' backpropagation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。