Efficient Neural Network Robustness Certification with General Activation Functions
Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, Luca Daniel
–Neural Information Processing Systems
Finding minimum distortion of adversarial examples and thus certifying robustness in neural network classifiers for given data points is known to be a challenging problem. Nevertheless, recently it has been shown to be possible to give a nontrivial certified lower bound of minimum adversarial distortion, and some recent progress has been made towards this direction by exploiting the piece-wise linear nature of ReLU activations. However, a generic robustness certification for general activation functions still remains largely unexplored.
Neural Information Processing Systems
Oct-8-2024, 04:42:42 GMT
- Country:
- North America > United States
- California (0.28)
- Massachusetts (0.28)
- North America > United States
- Genre:
- Research Report (0.46)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: