Deep Neural Networks (DNNs) are vulnerable to adversarial attacks. Existing methods are devoted to developing various robust training strategies or regularizations to update the weights of the neural network. But beyond the weights, the overall structure and information flow in the network are explicitly determined by the neural architecture, which remains unexplored. This paper thus aims to improve the adversarial robustness of the network from the architecture perspective. We explore the relationship among adversarial robustness, Lipschitz constant, and architecture parameters and show that an appropriate constraint on architecture parameters could reduce the Lipschitz constant to further improve the robustness. The importance of architecture parameters could vary from operation to operation or connection to connection. We approximate the Lipschitz constant of the entire network through a univariate log-normal distribution, whose mean and variance are related to architecture parameters. The confidence can be fulfilled through formulating a constraint on the distribution parameters based on the cumulative function. Compared with adversarially trained neural architectures searched by various NAS algorithms as well as efficient human-designed models, our algorithm empirically achieves the best performance among all the models under various attacks on different datasets.
翻译:深度神经网络(DNNs)易受对抗攻击。现有方法致力于开发各种鲁棒训练策略或正则化方法来更新神经网络的权重。然而,除权重之外,网络中的整体结构和信息流是由神经架构明确决定的,这一点尚未得到充分探索。本文旨在从架构角度提升网络的对抗鲁棒性。我们探索了对抗鲁棒性、Lipschitz常数和架构参数之间的关系,并表明对架构参数施加适当约束可以降低Lipschitz常数,从而进一步提高鲁棒性。架构参数的重要性可能因操作或连接而异。我们通过单变量对数正态分布来近似整个网络的Lipschitz常数,该分布的均值和方差与架构参数相关。通过基于累积函数对分布参数施加约束,可实现置信度。与通过各类神经架构搜索(NAS)算法搜索得到的对抗训练神经架构以及高效的人工设计模型相比,我们的算法在不同数据集上的多种攻击下,经验性地实现了所有模型中的最佳性能。