Robust Deep Learning as Optimal Control: Insights and Convergence Guarantees

Robust Deep Learning as Optimal Control: Insights and Convergence Guarantees
复制标题

鲁棒深度学习作为最优控制:见解和收敛保证

DOI:
--
复制
发表时间:
2020
期刊:
Conference on Learning for Dynamics & Control
影响因子:
--
通讯作者:
George Pappas
George Pappas
中科院分区:
--
文献类型:
--
作者:
Jacob H. Seidman;Mahyar Fazlyab;V. Preciado;George Pappas

文献摘要

被引文献

相似文献

深度神经网络对对抗选择输入的脆弱性促使人们需要重新审视深度学习算法。在训练过程中加入对抗性示例是一种流行的防御机制,以对抗对抗性攻击。这种机制可以被表述为最小-最大优化问题,其中对手试图使用迭代一阶算法最大化损失函数,而学习者则试图最小化损失函数。然而,以这种方式寻找对抗性示例会在训练期间造成过多的计算开销。通过将最小-最大问题解释为最优控制问题,最近的研究表明,人们可以在优化问题中利用神经网络的组合结构来显著提高训练时间。本文结合鲁棒最优控制技术和非精确oracle优化方法,首次对这种对抗训练算法进行收敛性分析。我们的分析揭示了算法的超参数如何影响其稳定性和收敛性。我们通过对一个鲁棒分类问题的实验来支持我们的见解。
The fragility of deep neural networks to adversarially-chosen inputs has motivated the need to revisit deep learning algorithms. Including adversarial examples during training is a popular defense mechanism against adversarial attacks. This mechanism can be formulated as a min-max optimization problem, where the adversary seeks to maximize the loss function using an iterative first-order algorithm while the learner attempts to minimize it. However, finding adversarial examples in this way causes excessive computational overhead during training. By interpreting the min-max problem as an optimal control problem, it has recently been shown that one can exploit the compositional structure of neural networks in the optimization problem to improve the training time significantly. In this paper, we provide the first convergence analysis of this adversarial training algorithm by combining techniques from robust optimal control and inexact oracle methods in optimization. Our analysis sheds light on how the hyperparameters of the algorithm affect the its stability and convergence. We support our insights with experiments on a robust classification problem.