Theoretical Analysis of Norm Selection for Robustness Verification of Neural Networks.

Saharat Saengsawang,Guoqiang Li
DOI: https://doi.org/10.1016/j.phycom.2023.102019
IF: 2.379
2023-01-01
Physical Communication
Abstract:In the robustness verification of neural network, L p-norm is generally used to measure the distance between two different data. However, different kinds of L p-norm examine the specific differences between each dimension of the data. Some L p-norm computational methods magnify specific differences between datasets. To verify the robustness of the network, the usual method is to calculate the different robustness radii of the L ∞-norm. But which L p norm performs best under a given network is rarely considered. To better reflect the nature of the network, this paper proposes a theoretical analysis of the robustness of the network that can be verified by choosing any norm type, and the relationship between the size of L p-ball corresponding to different robust radii is proved. We conducted experiments on different classification networks and obtained a general norm selection method. As a result, a specific norm can be considered first for network robustness without computing all the different L p-norm.
What problem does this paper attempt to address?