English

Provable robustness against all adversarial $l_p$-perturbations for $p\geq 1$

Machine Learning 2020-04-27 v2 Cryptography and Security Machine Learning

Abstract

In recent years several adversarial attacks and defenses have been proposed. Often seemingly robust models turn out to be non-robust when more sophisticated attacks are used. One way out of this dilemma are provable robustness guarantees. While provably robust models for specific lpl_p-perturbation models have been developed, we show that they do not come with any guarantee against other lql_q-perturbations. We propose a new regularization scheme, MMR-Universal, for ReLU networks which enforces robustness wrt l1l_1- and ll_\infty-perturbations and show how that leads to the first provably robust models wrt any lpl_p-norm for p1p\geq 1.

Keywords

Cite

@article{arxiv.1905.11213,
  title  = {Provable robustness against all adversarial $l_p$-perturbations for $p\geq 1$},
  author = {Francesco Croce and Matthias Hein},
  journal= {arXiv preprint arXiv:1905.11213},
  year   = {2020}
}