Deterministic Gaussian Averaged Neural Networks
Campbell, Ryan, Finlay, Chris, Oberman, Adam M
We present a deterministic method to compute the Gaussian average of neural networks used in regression and classification. Our method is based on an equivalence between training with a particular regularized loss, and the expected values of Gaussian averages. We use this equivalence to certify models which perform well on clean data but are not robust to adversarial perturbations. In terms of certified accuracy and adversarial robustness, our method is comparable to known stochastic methods such as randomized smoothing, but requires only a single model evaluation during inference.
Jun-10-2020
- Country:
- North America
- United States > California
- San Francisco County > San Francisco (0.14)
- Los Angeles County > Long Beach (0.14)
- San Diego County > San Diego (0.04)
- Canada
- Quebec > Montreal (0.14)
- British Columbia > Metro Vancouver Regional District
- Vancouver (0.05)
- Alberta > Census Division No. 15
- Improvement District No. 9 > Banff (0.04)
- United States > California
- Europe
- Asia > India
- Maharashtra > Pune (0.04)
- North America
- Genre:
- Research Report (1.00)
- Technology: