In this seminar I will talk about a provably stable architecture for Neural Ordinary Differential Equations (ODEs) which achieves non-trivial adversarial robustness under white-box adversarial attacks even when the network is trained naturally. For most existing defense methods withstanding strong white-box attacks, to improve robustness of neural networks, they need to be trained adversarially, hence have to strike a trade-off between natural accuracy and adversarial robustness. Inspired by dynamical system theory, we design a stabilized neural ODE network named SONet whose ODE blocks are skew-symmetric and proved to be input-output stable. With natural training, SONet can achieve comparable robustness with the state-of-art adversarial defense methods. In particular, under PGD-20 ($ell_infty=0.031$) attack on CIFAR-10 dataset, our method of natural training achieves 89.36% natural accuracy and 61.62% robust accuracy, while a counterpart architecture of ResNet trained with TRADES achieves natural and robust accuracy 85.28% and 23.06% respectively, in the same setting.
5月14日
4:00pm - 5:00pm
地点
https://hkust.zoom.us/j/98027512081
讲者/表演者
Mr. Yifei HUANG
HKUST
主办单位
Department of Mathematics
联系方法
mathseminar@ust.hk
付款详情
对象
Alumni, Faculty and Staff, PG Students, UG Students
语言
英语
其他活动
1月6日
研讨会, 演讲, 讲座
IAS / School of Science Joint Lecture - Innovations in Organo Rare-Earth and Titanium Chemistry: From Self-Healing Polymers to N2 Activation
Abstract In this lecture, the speaker will introduce their recent studies on the development of innovative organometallic complexes and catalysts aimed at realizing unprecedented chemical trans...
12月5日
研讨会, 演讲, 讲座
IAS / School of Science Joint Lecture - Human B Cell Receptor-Epitope Selection for Pan-Sarbecovirus Neutralization
Abstract The induction of broadly neutralizing antibodies (bnAbs) against viruses requires the specific activation of human B cell receptors (BCRs) by viral epitopes. Following BCR activation, ...