O N THE C ERTIFIED R OBUSTNESS FOR E NSEMBLE M ODELS AND B EYOND
O N THE C ERTIFIED R OBUSTNESS FOR E NSEMBLE M ODELS AND B EYOND
复制标题
DOI:
--
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Zhuolin Yang;Linyi Li;Xiaojun Xu;B. Kailkhura;Tao Xie;Bo Li
中科院分区:
文献类型:
--
作者:
Zhuolin Yang;Linyi Li;Xiaojun Xu;B. Kailkhura;Tao Xie;Bo Li
show deep neural networks (DNN) are vulnerable to adversarial which aim to mislead DNNs by adding perturbations with small magnitude. To defend against such attacks, both empirical and theoretical defense approaches have been extensively studied for a single ML model . In this work, we aim to analyze and provide the certified robustness for ensemble ML models , together with the sufficient and necessary conditions of robustness for different ensemble protocols. Although ensemble models are shown more robust than a single model empirically; surprisingly, we find that in terms of the certified robustness the standard ensemble models only achieve marginal improvement compared to a single model. Thus, to explore the conditions that guarantee to provide certifiably robust ensemble ML models, we first prove that diversified gradient and large confidence margin are sufficient and necessary conditions for certifiably robust ensemble models under the model-smoothness assumption. We then provide the bounded model-smoothness analysis based on the proposed Ensemble-before-Smoothing strategy. We also prove that an ensemble model can always achieve higher certified robustness than a single base model under mild conditions. Inspired by the theoretical findings, we propose the lightweight Diversity Regularized Training (DRT) to train certifiably robust ensemble ML models. Extensive experiments show that our DRT enhanced ensembles can consistently achieve higher certified robustness than existing single and ensemble ML models, demonstrating the state-of-the-art certified L 2 -robustness on MNIST, CIFAR-10, Models. For base models in our ensemble, we follow the configurations used in baselines: LeNet (Le-Cun et al., 1998), ResNet-110, and ResNet-50 (He et al., 2016) for MNIST, CIFAR-10, and ImageNet datasets respectively. Throughout the experiments, we use N = 3 base models to construct the ensemble for demonstration. We expect more base models would yield higher ensemble robustness. for training a robust ensemble. Our analysis provided the justification of the regularization-based training approach DRT. Extensive experiments showed that DRT-enhanced ensembles achieve the highest certified robustness compared with existing baselines.