Compositional Curvature Bounds for Deep Neural Networks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Entesari, Taha, Sharifi, Sina, Fazlyab, Mahyar
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909219377119232
author Entesari, Taha
Sharifi, Sina
Fazlyab, Mahyar
author_facet Entesari, Taha
Sharifi, Sina
Fazlyab, Mahyar
contents A key challenge that threatens the widespread use of neural networks in safety-critical applications is their vulnerability to adversarial attacks. In this paper, we study the second-order behavior of continuously differentiable deep neural networks, focusing on robustness against adversarial perturbations. First, we provide a theoretical analysis of robustness and attack certificates for deep classifiers by leveraging local gradients and upper bounds on the second derivative (curvature constant). Next, we introduce a novel algorithm to analytically compute provable upper bounds on the second derivative of neural networks. This algorithm leverages the compositional structure of the model to propagate the curvature bound layer-by-layer, giving rise to a scalable and modular approach. The proposed bound can serve as a differentiable regularizer to control the curvature of neural networks during training, thereby enhancing robustness. Finally, we demonstrate the efficacy of our method on classification tasks using the MNIST and CIFAR-10 datasets.
format Preprint
id arxiv_https___arxiv_org_abs_2406_05119
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Compositional Curvature Bounds for Deep Neural Networks
Entesari, Taha
Sharifi, Sina
Fazlyab, Mahyar
Machine Learning
Computer Vision and Pattern Recognition
A key challenge that threatens the widespread use of neural networks in safety-critical applications is their vulnerability to adversarial attacks. In this paper, we study the second-order behavior of continuously differentiable deep neural networks, focusing on robustness against adversarial perturbations. First, we provide a theoretical analysis of robustness and attack certificates for deep classifiers by leveraging local gradients and upper bounds on the second derivative (curvature constant). Next, we introduce a novel algorithm to analytically compute provable upper bounds on the second derivative of neural networks. This algorithm leverages the compositional structure of the model to propagate the curvature bound layer-by-layer, giving rise to a scalable and modular approach. The proposed bound can serve as a differentiable regularizer to control the curvature of neural networks during training, thereby enhancing robustness. Finally, we demonstrate the efficacy of our method on classification tasks using the MNIST and CIFAR-10 datasets.
title Compositional Curvature Bounds for Deep Neural Networks
topic Machine Learning
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2406.05119