Active subspace of neural networks: structural analysis and universal attacks

From MaRDI portal
Publication:5037556

DOI10.1137/19M1296070zbMATH Open1486.90152arXiv1910.13025OpenAlexW3095125464MaRDI QIDQ5037556FDOQ5037556


Authors: Chunfeng Cui, Kaiqi Zhang, T. Daulbaev, Julia Gusak, Ivan Oseledets, Zheng Zhang Edit this on Wikidata


Publication date: 1 March 2022

Published in: SIAM Journal on Mathematics of Data Science (Search for Journal in Brave)

Abstract: Active subspace is a model reduction method widely used in the uncertainty quantification community. In this paper, we propose analyzing the internal structure and vulnerability and deep neural networks using active subspace. Firstly, we employ the active subspace to measure the number of "active neurons" at each intermediate layer and reduce the number of neurons from several thousands to several dozens. This motivates us to change the network structure and to develop a new and more compact network, referred to as {ASNet}, that has significantly fewer model parameters. Secondly, we propose analyzing the vulnerability of a neural network using active subspace and finding an additive universal adversarial attack vector that can misclassify a dataset with a high probability. Our experiments on CIFAR-10 show that ASNet can achieve 23.98imes parameter and 7.30imes flops reduction. The universal active subspace attack vector can achieve around 20% higher attack ratio compared with the existing approach in all of our numerical experiments. The PyTorch codes for this paper are available online.


Full work available at URL: https://arxiv.org/abs/1910.13025




Recommendations




Cites Work


Cited In (5)

Uses Software





This page was built for publication: Active subspace of neural networks: structural analysis and universal attacks

Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q5037556)