CLIP: Cheap Lipschitz Training of Neural Networks
arXiv:2103.12531 · doi:10.1007/978-3-030-75549-2_25
Abstract
Despite the large success of deep neural networks (DNN) in recent years, most neural networks still lack mathematical guarantees in terms of stability. For instance, DNNs are vulnerable to small or even imperceptible input perturbations, so called adversarial examples, that can cause false predictions. This instability can have severe consequences in applications which influence the health and safety of humans, e.g., biomedical imaging or autonomous driving. While bounding the Lipschitz constant of a neural network improves stability, most methods rely on restricting the Lipschitz constants of each layer which gives a poor bound for the actual Lipschitz constant. In this paper we investigate a variational regularization method named CLIP for controlling the Lipschitz constant of a neural network, which can easily be integrated into the training procedure. We mathematically analyze the proposed model, in particular discussing the impact of the chosen regularization parameter on the output of the network. Finally, we numerically evaluate our method on both a nonlinear regression problem and the MNIST and Fashion-MNIST classification databases, and compare our results with a weight regularization approach.
12 pages, 2 figures, fixed a small mistake in the proof of Proposition 3, published at SSVM 2021
References in corpus (9)
- Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms
- WaveNet: A Generative Model for Raw Audio
- Deep Neural Networks with Trainable Activations and Controlled Lipschitz Constant
- Adversarial Training is a Form of Data-dependent Operator Norm Regularization
- Adversarial Lipschitz Regularization
- Variational regularisation for inverse problems with imperfect forward operators and general noise models
- Towards Rapid and Robust Adversarial Training with One-Step Attacks
- Lipschitz Bounds and Provably Robust Training by Laplacian Smoothing
- Large Norms of CNN Layers Do Not Hurt Adversarial Robustness