English

A Law of Robustness for Weight-bounded Neural Networks

Machine Learning 2021-03-15 v2 Machine Learning

Abstract

Robustness of deep neural networks against adversarial perturbations is a pressing concern motivated by recent findings showing the pervasive nature of such vulnerabilities. One method of characterizing the robustness of a neural network model is through its Lipschitz constant, which forms a robustness certificate. A natural question to ask is, for a fixed model class (such as neural networks) and a dataset of size nn, what is the smallest achievable Lipschitz constant among all models that fit the dataset? Recently, (Bubeck et al., 2020) conjectured that when using two-layer networks with kk neurons to fit a generic dataset, the smallest Lipschitz constant is Ω(nk)\Omega(\sqrt{\frac{n}{k}}). This implies that one would require one neuron per data point to robustly fit the data. In this work we derive a lower bound on the Lipschitz constant for any arbitrary model class with bounded Rademacher complexity. Our result coincides with that conjectured in (Bubeck et al., 2020) for two-layer networks under the assumption of bounded weights. However, due to our result's generality, we also derive bounds for multi-layer neural networks, discovering that one requires logn\log n constant-sized layers to robustly fit the data. Thus, our work establishes a law of robustness for weight bounded neural networks and provides formal evidence on the necessity of over-parametrization in deep learning.

Keywords

Cite

@article{arxiv.2102.08093,
  title  = {A Law of Robustness for Weight-bounded Neural Networks},
  author = {Hisham Husain and Borja Balle},
  journal= {arXiv preprint arXiv:2102.08093},
  year   = {2021}
}

Comments

The main result does not resolve the conjecture as claimed. However the proof technique can be used to obtain a weaker result. The manuscript will be updated at a later date