通过凸优化提升浅层网络对抗攻击鲁棒性
Convex training of Lipschitz-regularized shallow neural networks

- 将非凸的Lipschitz正则化训练转为可全局求解的凸问题
- 实验表明新方法在多个真实数据集上目标值更低、精度与鲁棒性更优
- 可作为后处理步骤,保证优化后性能不劣于初始模型
本文提出一种浅层神经网络的训练方法,以增强对对抗攻击的鲁棒性。通过引入凸约束,将原本非凸的Lipschitz正则化训练问题转化为可高效求得全局最优的凸问题。该方法可作为后处理步骤:以预训练网络为初始解,求解凸程序,所得最优网络性能不低于初始模型。在真实世界回归数据集上的对抗环境下实验表明,本方法在数值上优于现有方法,目标值更低;部分数据集上,新网络不仅更准确,且对对抗攻击更具鲁棒性。
原文摘要 · Abstract (English)
In this work, we introduce a training procedure for shallow neural networks that promotes robustness against adversarial attacks. We solve a non-convex Lipschitz-regularized training program by introducing a convex restriction that can be efficiently solved to global optimality. Our approach can be employed as a post-processing step by taking a pre-trained network as an initial solution to then solving the convex program whose optimal network is guaranteed to be no worse than the initial one. We illustrate the improvements of our training procedure with experiments using real world datasets for regression tasks under an adversarial setting. We show numerically that solving our proposed convex program yields networks with lower objective values on the Lipschitz-regularized program compared to existing methods. Additionally, we show that on certain datasets, networks obtained using our convex training program are both more accurate and robust with respect to adversarial attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。