Adversarial Robustness of Sparse Local Lipschitz Predictors
From MaRDI portal
Abstract: This work studies the adversarial robustness of parametric functions composed of a linear predictor and a non-linear representation map. % that satisfies certain stability condition. Our analysis relies on emph{sparse local Lipschitzness} (SLL), an extension of local Lipschitz continuity that better captures the stability and reduced effective dimensionality of predictors upon local perturbations. SLL functions preserve a certain degree of structure, given by the sparsity pattern in the representation map, and include several popular hypothesis classes, such as piece-wise linear models, Lasso and its variants, and deep feed-forward
elu networks. % are sparse local Lipschitz. We provide a tighter robustness certificate on the minimal energy of an adversarial example, as well as tighter data-dependent non-uniform bounds on the robust generalization error of these predictors. We instantiate these results for the case of deep neural networks and provide numerical evidence that supports our results, shedding new insights into natural regularization strategies to increase the robustness of these models.
Cites work
- Analysis of classifiers' robustness to adversarial perturbations
- Foundations of machine learning
- scientific article; zbMATH DE number 845714 (Why is no real title available?)
- Learning under p-tampering attacks
- Lipschitz Certificates for Layered Network Structures Driven by Averaged Activation Operators
- Size-independent sample complexity of neural networks
This page was built for publication: Adversarial Robustness of Sparse Local Lipschitz Predictors
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q6070302)