ResearchTrend.AI
  • Papers
  • Communities
  • Events
  • Blog
  • Pricing
Papers
Communities
Social Events
Terms and Conditions
Pricing
Parameter LabParameter LabTwitterGitHubLinkedInBlueskyYoutube

© 2025 ResearchTrend.AI, All rights reserved.

  1. Home
  2. Papers
  3. 2102.05363
80
51
v1v2v3v4 (latest)

Towards Certifying L-infinity Robustness using Neural Networks with L-inf-dist Neurons

10 February 2021
Bohang Zhang
Tianle Cai
Zhou Lu
Di He
Liwei Wang
    OOD
ArXiv (abs)PDFHTML
Abstract

It is well-known that standard neural networks, even with a high classification accuracy, are vulnerable to small ℓ∞\ell_\inftyℓ∞​-norm bounded adversarial perturbations. Although many attempts have been made, most previous works either can only provide empirical verification of the defense to a particular attack method, or can only develop a certified guarantee of the model robustness in limited scenarios. In this paper, we seek for a new approach to develop a theoretically principled neural network that inherently resists ℓ∞\ell_\inftyℓ∞​ perturbations. In particular, we design a novel neuron that uses ℓ∞\ell_\inftyℓ∞​-distance as its basic operation (which we call ℓ∞\ell_\inftyℓ∞​-dist neuron), and show that any neural network constructed with ℓ∞\ell_\inftyℓ∞​-dist neurons (called ℓ∞\ell_{\infty}ℓ∞​-dist net) is naturally a 1-Lipschitz function with respect to ℓ∞\ell_\inftyℓ∞​-norm. This directly provides a rigorous guarantee of the certified robustness based on the margin of prediction outputs. We also prove that such networks have enough expressive power to approximate any 1-Lipschitz function with robust generalization guarantee. Our experimental results show that the proposed network is promising. Using ℓ∞\ell_{\infty}ℓ∞​-dist nets as the basic building blocks, we consistently achieve state-of-the-art performance on commonly used datasets: 93.09% certified accuracy on MNIST (ϵ=0.3\epsilon=0.3ϵ=0.3), 79.23% on Fashion MNIST (ϵ=0.1\epsilon=0.1ϵ=0.1) and 35.10% on CIFAR-10 (ϵ=8/255\epsilon=8/255ϵ=8/255).

View on arXiv
Comments on this paper