paper-with-me

홈 › Papers

Lipschitz-Certifiable Training with a Tight Outer Bound

2020-12-01 · NeurIPS 2020 12 · Sungyoon Lee, Jaewook Lee, Saerom Park

Verifiable training is a promising research direction for training a robust network. However, most verifiable training methods are slow or lack scalability. In this study, we propose a fast and scalable certifiable training algorithm based on Lipschitz analysis and interval arithmetic. Our certifiable training algorithm provides a tight propagated outer bound by introducing the box constraint propagation (BCP), and it efficiently computes the worst logit over the outer bound. In the experiments, we show that BCP achieves a tighter outer bound than the global Lipschitz-based outer bound. Moreover, our certifiable training algorithm is over 12 times faster than the state-of-the-art dual relaxation-based method; however, it achieves comparable or better verification performance, improving natural accuracy. Our fast certifiable training algorithm with the tight outer bound can scale to Tiny ImageNet with verification accuracy of 20.1\% ($\ell_2$-perturbation of $\epsilon=36/255$). Our code is available at \url{https://github.com/sungyoon-lee/bcp}.

📄 PDF Abstract BibTeX

Code (1)

sungyoon-lee/bcp 공식 구현 pytorch

Similar Papers 제목 키워드 기반

Training Certifiably Robust Neural Networks with Efficient Local Lipschitz Bounds

2021-11-02 · NeurIPS 2021 12 · Yujia Huang, huan zhang, Yuanyuan Shi, J Zico Kolter 외

Certified robustness is a desirable property for deep neural networks in safety-critical applications, and popular training algorithms can certify robustness of a neural network by computing a global bound on its Lipschi…

Lipschitz-Based Robustness Certification for Recurrent Neural Networks via Convex Relaxation

2025-09-22 · Paul Hamelbeck, Johannes Schiffer arxiv

Robustness certification against bounded input noise or adversarial perturbations is increasingly important for deployment recurrent neural networks (RNNs) in safety-critical control applications. To address this challen…

1-Lipschitz Layers Compared: Memory, Speed, and Certifiable Robustness

2023-11-28 · Bernd Prach, Fabio Brau, Giorgio Buttazzo, Christoph H. Lampert

The robustness of neural networks against input perturbations with bounded magnitude represents a serious concern in the deployment of deep learning models in safety-critical systems. Recently, the scientific community h…

Globally-Robust Neural Networks

2021-02-16 · Klas Leino, Zifan Wang, Matt Fredrikson

The threat of adversarial examples has motivated work on training certifiably robust neural networks to facilitate efficient verification of local robustness at inference time. We formalize a notion of global robustness,…

1-Lipschitz Layers Compared: Memory Speed and Certifiable Robustness

2024-01-01 · CVPR 2024 1 · Bernd Prach, Fabio Brau, Giorgio Buttazzo, Christoph H. Lampert

The robustness of neural networks against input perturbations with bounded magnitude represents a serious concern in the deployment of deep learning models in safety-critical systems. Recently the scientific communit…