Reviews: Sparse DNNs with Improved Adversarial Robustness
–Neural Information Processing Systems
This paper assumes an intrinsic relationship between the sparsity and the robustness of DNN models. The authors prove that this assumption holds for linear models under the l_infinity attacker model, and it also holds for nonlinear models under both l_2 and l_infinity attacker models. Then, the authors demonstrate some experimental results which are consistent with the theory. In general, this paper is well-written, and it is a plausible investigation on the issues of DNN robustness. The problem studied in this paper is very important and also challenging.
Neural Information Processing Systems
Oct-7-2024, 09:55:36 GMT