Robust Generalization of Quadratic Neural Networks via Function Identification
arXiv:2109.10935
Abstract
A key challenge facing deep learning is that neural networks are often not robust to shifts in the underlying data distribution. We study this problem from the perspective of the statistical concept of parameter identification. Generalization bounds from learning theory often assume that the test distribution is close to the training distribution. In contrast, if we can identify the "true" parameters, then the model generalizes to arbitrary distribution shifts. However, neural networks typically have internal symmetries that make parameter identification impossible. We show that we can identify the function represented by a quadratic network even though we cannot identify its parameters; we extend this result to neural networks with ReLU activations. Thus, we can obtain robust generalization bounds for neural networks. We leverage this result to obtain new bounds for contextual bandits and transfer learning with quadratic neural networks. Overall, our results suggest that we can improve robustness of neural networks by designing models that can represent the true data generating process.
References in corpus (12)
- Certified Adversarial Robustness via Randomized Smoothing
- Exploring Generalization in Deep Learning
- WILDS: A Benchmark of in-the-Wild Distribution Shifts
- Measuring Robustness to Natural Distribution Shifts in Image Classification
- Learning One-hidden-layer Neural Networks with Landscape Design
- Convex Sparse Matrix Factorizations
- Certified Defenses for Data Poisoning Attacks
- A Benchmark for Systematic Generalization in Grounded Language Understanding
- Neural Contextual Bandits with UCB-based Exploration
- The Implicit Regularization of Stochastic Gradient Flow for Least Squares
- Identifiability and Unmixing of Latent Parse Trees
- Group-Sparse Matrix Factorization for Transfer Learning of Word Embeddings