Robust Deep Learning as Optimal Control: Insights and Convergence Guarantees

05/01/2020
by   Jacob H. Seidman, et al.
12

The fragility of deep neural networks to adversarially-chosen inputs has motivated the need to revisit deep learning algorithms. Including adversarial examples during training is a popular defense mechanism against adversarial attacks. This mechanism can be formulated as a min-max optimization problem, where the adversary seeks to maximize the loss function using an iterative first-order algorithm while the learner attempts to minimize it. However, finding adversarial examples in this way causes excessive computational overhead during training. By interpreting the min-max problem as an optimal control problem, it has recently been shown that one can exploit the compositional structure of neural networks in the optimization problem to improve the training time significantly. In this paper, we provide the first convergence analysis of this adversarial training algorithm by combining techniques from robust optimal control and inexact oracle methods in optimization. Our analysis sheds light on how the hyperparameters of the algorithm affect the its stability and convergence. We support our insights with experiments on a robust classification problem.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/08/2020

Evaluation of Adversarial Training on Different Types of Neural Networks in Deep Learning-based IDSs

Network security applications, including intrusion detection systems of ...
research
12/15/2021

On the Convergence and Robustness of Adversarial Training

Improving the robustness of deep neural networks (DNNs) to adversarial e...
research
05/02/2019

You Only Propagate Once: Painless Adversarial Training Using Maximal Principle

Deep learning achieves state-of-the-art results in many areas. However r...
research
09/13/2021

On the regularized risk of distributionally robust learning over deep neural networks

In this paper we explore the relation between distributionally robust le...
research
05/02/2019

You Only Propagate Once: Accelerating Adversarial Training Using Maximal Principle

Deep learning achieves state-of-the-art results in many areas. However r...
research
12/23/2021

Revisiting and Advancing Fast Adversarial Training Through The Lens of Bi-Level Optimization

Adversarial training (AT) has become a widely recognized defense mechani...
research
10/16/2020

Learning Robust Algorithms for Online Allocation Problems Using Adversarial Training

We address the challenge of finding algorithms for online allocation (i....

Please sign up or login with your details

Forgot password? Click here to reset