BOOSTING THE CERTIFIED ROBUSTNESS OF L-INFINITY DISTANCE NETS

Bohang Zhang1 Du Jiang Di He, Liwei Wang
2021-10-01
Abstract:Recently, Zhang et al.(2021) developed a new neural network architecture based on l∞-distance functions, which naturally possesses certified l∞ robustness by its construction. Despite rigorous theoretical guarantees, the model so far can only achieve comparable performance to conventional networks. In this paper, we make the following two contributions:(i) We demonstrate that l∞-distance nets enjoy a fundamental advantage in certified robustness over conventional networks (under typical certification approaches);(ii) With an improved training process we are able to significantly boost the certified accuracy of l∞-distance nets. Our training approach largely alleviates the optimization problem that arose in the previous training scheme, in particular, the unexpected large Lipschitz constant due to the use of a crucial trick called lp-relaxation. The core of our training approach is a novel objective function that combines scaled cross-entropy loss and clipped hinge loss with a decaying mixing coefficient. Experiments show that using the proposed training strategy, the certified accuracy of l∞-distance net can be dramatically improved from 33.30% to 40.06% on CIFAR-10 (ϵ= 8/255), meanwhile outperforming other approaches in this area by a large margin. Our results clearly demonstrate the effectiveness and potential of l∞-distance net for certified robustness. Codes are available at https://github. com/zbh2047/L inf-dist-net-v2.
What problem does this paper attempt to address?