Certified Robustness for Deep Equilibrium Models via Serialized Random Smoothing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gao, Weizhi, Hou, Zhichao, Xu, Han, Liu, Xiaorui
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909375769083904
author Gao, Weizhi
Hou, Zhichao
Xu, Han
Liu, Xiaorui
author_facet Gao, Weizhi
Hou, Zhichao
Xu, Han
Liu, Xiaorui
contents Implicit models such as Deep Equilibrium Models (DEQs) have emerged as promising alternative approaches for building deep neural networks. Their certified robustness has gained increasing research attention due to security concerns. Existing certified defenses for DEQs employing deterministic certification methods such as interval bound propagation and Lipschitz-bounds can not certify on large-scale datasets. Besides, they are also restricted to specific forms of DEQs. In this paper, we provide the first randomized smoothing certified defense for DEQs to solve these limitations. Our study reveals that simply applying randomized smoothing to certify DEQs provides certified robustness generalized to large-scale datasets but incurs extremely expensive computation costs. To reduce computational redundancy, we propose a novel Serialized Randomized Smoothing (SRS) approach that leverages historical information. Additionally, we derive a new certified radius estimation for SRS to theoretically ensure the correctness of our algorithm. Extensive experiments and ablation studies on image recognition demonstrate that our algorithm can significantly accelerate the certification of DEQs by up to 7x almost without sacrificing the certified accuracy. Our code is available at https://github.com/WeizhiGao/Serialized-Randomized-Smoothing.
format Preprint
id arxiv_https___arxiv_org_abs_2411_00899
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Certified Robustness for Deep Equilibrium Models via Serialized Random Smoothing
Gao, Weizhi
Hou, Zhichao
Xu, Han
Liu, Xiaorui
Machine Learning
Artificial Intelligence
Implicit models such as Deep Equilibrium Models (DEQs) have emerged as promising alternative approaches for building deep neural networks. Their certified robustness has gained increasing research attention due to security concerns. Existing certified defenses for DEQs employing deterministic certification methods such as interval bound propagation and Lipschitz-bounds can not certify on large-scale datasets. Besides, they are also restricted to specific forms of DEQs. In this paper, we provide the first randomized smoothing certified defense for DEQs to solve these limitations. Our study reveals that simply applying randomized smoothing to certify DEQs provides certified robustness generalized to large-scale datasets but incurs extremely expensive computation costs. To reduce computational redundancy, we propose a novel Serialized Randomized Smoothing (SRS) approach that leverages historical information. Additionally, we derive a new certified radius estimation for SRS to theoretically ensure the correctness of our algorithm. Extensive experiments and ablation studies on image recognition demonstrate that our algorithm can significantly accelerate the certification of DEQs by up to 7x almost without sacrificing the certified accuracy. Our code is available at https://github.com/WeizhiGao/Serialized-Randomized-Smoothing.
title Certified Robustness for Deep Equilibrium Models via Serialized Random Smoothing
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2411.00899