Developing robust sparse models fit for safety-critical and resource-constrained systems such as drones, autonomous robots, etc., has been an issue of longstanding interest. The inability of adversarial training mechanisms to provide a formal robustness guarantee kindles the requirement for verified local robustness mechanisms. This work aims to compute sparse verified locally robust networks which exhibit (benign) accuracy and verified local robustness comparable to their dense counterparts. Towards this objective, we examine several model sparsification approaches and present `SparseVLR'-- a framework to search verified locally robust sparse networks. We empirically investigated SparseVLR's efficacy and generalizability by evaluating various benchmark and application-specific datasets across several models. Above all, we provide an in-depth study and reasoning to unveil the causes for the ascendancy of SparseVLR.
翻译:开发适用于无人机、自主机器人等安全关键且资源受限系统的鲁棒稀疏模型,一直是长期关注的问题。对抗训练机制无法提供形式化鲁棒性保证,这激发了对验证局部鲁棒性机制的需求。本文旨在计算稀疏的验证局部鲁棒网络,这些网络在良性精度和验证局部鲁棒性方面与其稠密对应物相当。为此,我们研究了多种模型稀疏化方法,并提出了SparseVLR——一种用于搜索验证局部鲁棒稀疏网络的框架。我们通过跨多个模型评估各种基准数据集和特定应用数据集,实证研究了SparseVLR的有效性和泛化能力。最重要的是,我们进行了深入研究和推理,揭示了SparseVLR优势的内在原因。