Article(id=1241719282455868370, tenantId=1146029695717560320, journalId=1146032081894723586, issueId=1241719216169079576, articleNumber=null, orderNo=7, doi=10.3981/j.issn.2097-0781.2023.01.006, pmid=null, cstr=null, oa=null, hot=null, price=null, onlineType=0, articleFormat=0, articleType=null, articleTypeStr=research-article, receivedDate=1671811200000, receivedDateStr=2022-12-24, revisedDate=1675180800000, revisedDateStr=2023-02-01, acceptedDate=null, acceptedDateStr=null, onlineDate=1679846400000, onlineDateStr=2023-03-27, pubDate=1679241600000, pubDateStr=2023-03-20, doiRegisterDate=null, doiRegisterDateStr=null, onlineIssueDate=1679846400000, onlineIssueDateStr=2023-03-27, onlineJustAcceptDate=null, onlineJustAcceptDateStr=null, onlineFirstDate=null, onlineFirstDateStr=null, sourceXml=null, magXml=null, createTime=1773978546965, creator=sys-migrate, updateTime=1773978546965, updator=sys-migrate, issue=Issue{id=1241719216169079576, tenantId=1146029695717560320, journalId=1146032081894723586, year='2023', volume='2', issue='1', pageStart='5', pageEnd='143', issueExtLink='null', onlineDate='null', pubDate='1679241600000', pubDateStr='2023-03-20', beforeIssueId=null, nextIssueId=null, price=null, status=1, issueComplete=1, articleOrder=1, issueType=-1, specialIssue=1, createTime=1773978531159, creator='sys-migrate', updateTime=1774001248771, updator='13041195026', preIssue=null, nextIssue=null, articleTotal=null, ext={EN=IssueExt(id=1241814500781916967, tenantId=1146029695717560320, journalId=1146032081894723586, issueId=1241719216169079576, language=EN, specialIssueTitle=Science and Technology Foresight, coverIllustrator=null, specialIssueEditor=null, specialIssueAbout=null), CN=IssueExt(id=1241814500781916968, tenantId=1146029695717560320, journalId=1146032081894723586, issueId=1241719216169079576, language=CN, specialIssueTitle=形式化方法与复杂计算系统可信保障, coverIllustrator=null, specialIssueEditor=null, specialIssueAbout=null)}, issueFiles=null, downloadFileDto=null}, startPage=78, endPage=89, ext={EN=ArticleExt(id=1241719287749070898, articleId=1241719282455868370, tenantId=1146029695717560320, journalId=1146032081894723586, language=EN, title=Advances and Prospects of Training Methods for Robust Neural Networks, columnId=1149656489310208610, journalTitle=Science and Technology Foresight, columnName=Review and Commentary, runingTitle=null, highlight=null, articleAbstract=

In recent years, deep neural networks have developed into important computing models for deep learning, whose robustness is essential for their deployment in safety-critical areas. Therefore, the way to train robust neural networks is a popular issue that has attracted the attention of academia and industry. In this paper, three mainstream classes of training methods for robust neural networks are introduced, i.e., the method based on data enhancement, that based on adversarial training, and the Lipschitz robust training method. Meanwhile, their core ideas, representative work, and the application scope are introduced. Then, the advantages and disadvantages of the training methods in recent years are compared, and in-depth analysis and comparison are carried out when they correspond to key elements in neural network training. The robustness evaluation metrics of neural networks obtained by these training methods are introduced and compared. Finally, hotspots and challenges of robust neural network training are analyzed, and the possible future directions and some suggestions are briefly summarized.

, authors=null, authorsList=Zhen LIANG, Wanwei LIU, Taoran WU, Dejin REN, Bai XUE, authorCompany=null, correspAuthors=Wanwei LIU, authorNote=null, correspAuthorsNote=
, copyrightStatement=null, copyrightOwner=null, extLink=null, articleAbsUrl=null, sourceXml=null, magXml=null, pdfUrl=null, pdf=null, pdfFileSize=null, pdfExtLink=null, richHtmlUrl=null, mobilePdfUrl=null, reviewReport=null, pdfFirstPage=null, abstractGraph=null, abstractGraphContent=null, abstractVideo=null, citation=null, cebUrl=null, magXmlContent=null, mapNumber=null, fund=null), CN=ArticleExt(id=1241719287627436081, articleId=1241719282455868370, tenantId=1146029695717560320, journalId=1146032081894723586, language=CN, title=鲁棒神经网络的训练方法研究进展与前景, columnId=1148708266483446458, journalTitle=前瞻科技, columnName=综述与述评, runingTitle=null, highlight=null, articleAbstract=

近年来,深度神经网络已经发展成为深度学习的重要计算模型,神经网络的鲁棒性对于其在安全攸关领域的部署至关重要。因此,如何训练鲁棒的神经网络是备受学术界和工业界关注的热点问题。文章介绍了目前主流的3类鲁棒神经网络的训练方法,即基于数据增强训练、基于对抗训练和利普希茨鲁棒性训练;并介绍了其各自方法的核心思想、代表性研究工作和适用范围。同时,将近年来的鲁棒神经网络训练方法的优缺点进行比较,对应到神经网络训练的要素上进行深入分析和对照,并对各类训练方法得到的神经网络的鲁棒性的评价指标进行了介绍和比较。最后,分析了目前鲁棒神经网络训练的难点和热点,展望了该领域可能的研究方向,并提出建议。

, authors=

梁震,博士研究生。主要研究方向为AI可解释性与AI形式化验证等。电子信箱:

刘万伟,教授,中国计算机学会高级会员。主要研究方向为自动机理论、形式化方法、AI形式化验证等。在IEEE Transactions on Sustainable Energy、ACM Transactions on Quantum Computing、ICSE、ASE、CAV、TACAS、IJCAI等期刊/会议发表多篇论文。参与开发的验证工具在TACAS SV-comp比赛中多次获得第一名。电子信箱:

, authorsList=梁震, 刘万伟, 吴陶然, 任德金, 薛白, authorCompany=null, correspAuthors=刘万伟, authorNote=null, correspAuthorsNote=
, copyrightStatement=null, copyrightOwner=null, extLink=null, articleAbsUrl=null, sourceXml=Fbl2ZbozkYYotdt3pUmw5Q==, magXml=NHsvYQOvXV/EJQLlCDqAcQ==, pdfUrl=null, pdf=WFHE1R8OvdX6E49cxUywdg==, pdfFileSize=2310215, pdfExtLink=null, richHtmlUrl=null, mobilePdfUrl=null, reviewReport=null, pdfFirstPage=null, abstractGraph=null, abstractGraphContent=null, abstractVideo=null, citation=null, cebUrl=null, magXmlContent=Q6oegHS6TGsG8g6JaHauww==, mapNumber=null, fund=null)}, authors=[Author(id=1241719294355099740, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, orderNo=0, firstName=null, middleName=null, lastName=null, nameCn=null, orcid=null, stid=null, country=null, authorPic=null, dead=0, email=liangzhen@nudt.edu.cn, emailSecond=null, emailThird=null, correspondingAuthor=0, authorType=1, ext={EN=AuthorExt(id=1241719294451568734, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, authorId=1241719294355099740, language=EN, stringName=Zhen LIANG, firstName=Zhen, middleName=null, lastName=LIANG, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=1, address=1. Institute of Quantum Information & State Key Laboratory of High Performance Computing, National University of Defense Technology, Changsha 410073, China, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null), CN=AuthorExt(id=1241719294535454815, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, authorId=1241719294355099740, language=CN, stringName=梁震, firstName=null, middleName=null, lastName=null, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=1, address=1.国防科技大学量子信息研究所兼高性能计算国家重点实验室,长沙 410073, bio={"img":"SUSmSf/Aez3m1Eg2MVz6cA==","content":"

梁震,博士研究生。主要研究方向为AI可解释性与AI形式化验证等。电子信箱:

"}, bioImg=SUSmSf/Aez3m1Eg2MVz6cA==, bioContent=

梁震,博士研究生。主要研究方向为AI可解释性与AI形式化验证等。电子信箱:

, aboutCorrespAuthor=null)}, companyList=[AuthorCompany(id=1241719293860171852, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719293868560461, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719293860171852, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=1. Institute of Quantum Information & State Key Laboratory of High Performance Computing, National University of Defense Technology, Changsha 410073, China), AuthorCompanyExt(id=1241719293885337679, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719293860171852, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=1.国防科技大学量子信息研究所兼高性能计算国家重点实验室,长沙 410073)])]), Author(id=1241719296007655527, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, orderNo=1, firstName=null, middleName=null, lastName=null, nameCn=null, orcid=null, stid=null, country=null, authorPic=null, dead=0, email=wwliu@nudt.edu.cn, emailSecond=null, emailThird=null, correspondingAuthor=1, authorType=1, ext={EN=AuthorExt(id=1241719296108318829, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, authorId=1241719296007655527, language=EN, stringName=Wanwei LIU, firstName=Wanwei, middleName=null, lastName=LIU, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=2, , address=2. College of Computer Science and Technology, National University of Defense Technology, Changsha 410073, China, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null), CN=AuthorExt(id=1241719296200593520, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, authorId=1241719296007655527, language=CN, stringName=刘万伟, firstName=null, middleName=null, lastName=null, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=2, , address=2.国防科技大学计算机学院,长沙 410073, bio={"img":"DBy2ZWzdzkkCtEFYOlbHvg==","content":"

刘万伟,教授,中国计算机学会高级会员。主要研究方向为自动机理论、形式化方法、AI形式化验证等。在IEEE Transactions on Sustainable Energy、ACM Transactions on Quantum Computing、ICSE、ASE、CAV、TACAS、IJCAI等期刊/会议发表多篇论文。参与开发的验证工具在TACAS SV-comp比赛中多次获得第一名。电子信箱:

"}, bioImg=DBy2ZWzdzkkCtEFYOlbHvg==, bioContent=

刘万伟,教授,中国计算机学会高级会员。主要研究方向为自动机理论、形式化方法、AI形式化验证等。在IEEE Transactions on Sustainable Energy、ACM Transactions on Quantum Computing、ICSE、ASE、CAV、TACAS、IJCAI等期刊/会议发表多篇论文。参与开发的验证工具在TACAS SV-comp比赛中多次获得第一名。电子信箱:

, aboutCorrespAuthor=null)}, companyList=[AuthorCompany(id=1241719293956640849, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719293965029458, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719293956640849, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=2. College of Computer Science and Technology, National University of Defense Technology, Changsha 410073, China), AuthorCompanyExt(id=1241719293973418067, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719293956640849, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=2.国防科技大学计算机学院,长沙 410073)])]), Author(id=1241719296297062517, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, orderNo=2, firstName=null, middleName=null, lastName=null, nameCn=null, orcid=null, stid=null, country=null, authorPic=null, dead=0, email=null, emailSecond=null, emailThird=null, correspondingAuthor=0, authorType=1, ext={EN=AuthorExt(id=1241719296544526463, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, authorId=1241719296297062517, language=EN, stringName=Taoran WU, firstName=Taoran, middleName=null, lastName=WU, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=3, 4, address=3. State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
4. School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing 100190, China, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null), CN=AuthorExt(id=1241719296640995458, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, authorId=1241719296297062517, language=CN, stringName=吴陶然, firstName=null, middleName=null, lastName=null, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=3, 4, address=3.中国科学院软件研究所计算机科学国家重点实验室,北京 100190
4.中国科学院大学计算机科学与技术学院,北京 100190, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null)}, companyList=[AuthorCompany(id=1241719294053109845, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719294061498454, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294053109845, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=3. State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China), AuthorCompanyExt(id=1241719294069887063, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294053109845, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=3.中国科学院软件研究所计算机科学国家重点实验室,北京 100190)]), AuthorCompany(id=1241719294141190232, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719294149578841, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294141190232, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=4. School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing 100190, China), AuthorCompanyExt(id=1241719294157967450, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294141190232, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=4.中国科学院大学计算机科学与技术学院,北京 100190)])]), Author(id=1241719296724881543, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, orderNo=3, firstName=null, middleName=null, lastName=null, nameCn=null, orcid=null, stid=null, country=null, authorPic=null, dead=0, email=null, emailSecond=null, emailThird=null, correspondingAuthor=0, authorType=1, ext={EN=AuthorExt(id=1241719296821350539, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, authorId=1241719296724881543, language=EN, stringName=Dejin REN, firstName=Dejin, middleName=null, lastName=REN, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=3, 4, address=3. State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
4. School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing 100190, China, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null), CN=AuthorExt(id=1241719296968151181, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, authorId=1241719296724881543, language=CN, stringName=任德金, firstName=null, middleName=null, lastName=null, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=3, 4, address=3.中国科学院软件研究所计算机科学国家重点实验室,北京 100190
4.中国科学院大学计算机科学与技术学院,北京 100190, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null)}, companyList=[AuthorCompany(id=1241719294053109845, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719294061498454, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294053109845, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=3. State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China), AuthorCompanyExt(id=1241719294069887063, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294053109845, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=3.中国科学院软件研究所计算机科学国家重点实验室,北京 100190)]), AuthorCompany(id=1241719294141190232, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719294149578841, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294141190232, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=4. School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing 100190, China), AuthorCompanyExt(id=1241719294157967450, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294141190232, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=4.中国科学院大学计算机科学与技术学院,北京 100190)])]), Author(id=1241719297077203090, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, orderNo=4, firstName=null, middleName=null, lastName=null, nameCn=null, orcid=null, stid=null, country=null, authorPic=null, dead=0, email=null, emailSecond=null, emailThird=null, correspondingAuthor=0, authorType=1, ext={EN=AuthorExt(id=1241719297177866390, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, authorId=1241719297077203090, language=EN, stringName=Bai XUE, firstName=Bai, middleName=null, lastName=XUE, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=3, address=3. State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null), CN=AuthorExt(id=1241719297278529688, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, authorId=1241719297077203090, language=CN, stringName=薛白, firstName=null, middleName=null, lastName=null, prefix=null, suffix=null, authorComment=null, nameInitials=null, affiliation=null, department=null, xref=3, address=3.中国科学院软件研究所计算机科学国家重点实验室,北京 100190, bio=null, bioImg=null, bioContent=null, aboutCorrespAuthor=null)}, companyList=[AuthorCompany(id=1241719294053109845, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719294061498454, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294053109845, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=3. State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China), AuthorCompanyExt(id=1241719294069887063, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294053109845, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=3.中国科学院软件研究所计算机科学国家重点实验室,北京 100190)])])], keywords=[Keyword(id=1241719297416941725, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, language=EN, orderNo=1, keyword=deep neural network), Keyword(id=1241719297630851232, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, language=EN, orderNo=2, keyword=robustness), Keyword(id=1241719297718931619, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, language=EN, orderNo=3, keyword=neural network training), Keyword(id=1241719297807012006, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, language=CN, orderNo=1, keyword=深度神经网络), Keyword(id=1241719297865732264, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, language=CN, orderNo=2, keyword=鲁棒性), Keyword(id=1241719297928646826, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, language=CN, orderNo=3, keyword=神经网络训练)], refs=[Reference(id=1241719298599735488, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2021, volume=34, issue=null, pageStart=5236, pageEnd=5249, url=null, language=null, rfNumber=[1], rfOrder=0, authorNames=Karch T, Teodorescu L, Hofmann K, journalName=Advances in Neural Information Processing Systems, refType=null, unstructuredReference=Karch T, Teodorescu L, Hofmann K, et al. Grounding spatio-temporal language with transformers[J]. Advances in Neural Information Processing Systems, 2021, 34: 5236-5249., articleTitle=Grounding spatio-temporal language with transformers, refAbstract=null), Reference(id=1241719298679427269, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2021, volume=34, issue=null, pageStart=6542, pageEnd=6554, url=null, language=null, rfNumber=[2], rfOrder=1, authorNames=Wang J, Wang K C, Rudzicz F, journalName=Advances in Neural Information Processing Systems, refType=null, unstructuredReference=Wang J, Wang K C, Rudzicz F, et al. Grad2Task: Improved few-shot text classification using gradients for task representation[J]. Advances in Neural Information Processing Systems, 2021, 34: 6542-6554., articleTitle=Grad2Task: Improved few-shot text classification using gradients for task representation, refAbstract=null), Reference(id=1241719298767507657, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2021, volume=34, issue=null, pageStart=8282, pageEnd=8293, url=null, language=null, rfNumber=[3], rfOrder=2, authorNames=Dahnert M, Hou J, Nießner M, journalName=Advances in Neural Information Processing Systems, refType=null, unstructuredReference=Dahnert M, Hou J, Nießner M, et al. Panoptic 3D scene reconstruction from a single RGB image[J]. Advances in Neural Information Processing Systems, 2021, 34: 8282-8293., articleTitle=Panoptic 3D scene reconstruction from a single RGB image, refAbstract=null), Reference(id=1241719298847199435, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=10.1364/AO.432397, pmid=null, pmcid=null, year=2021, volume=60, issue=24, pageStart=7466, pageEnd=7479, url=https://opg.optica.org/abstract.cfm?URI=ao-60-24-7466, language=null, rfNumber=[4], rfOrder=3, authorNames=Tian Y, Yang W, Wang J, journalName=Applied Optics, refType=null, unstructuredReference=Tian Y, Yang W, Wang J. Image fusion using a multi-level image decomposition and fusion method[J]. Applied Optics, 2021, 60(24): 7466-7479., articleTitle=Image fusion using a multi-level image decomposition and fusion method, refAbstract=In recent years, image fusion has emerged as an important research field due to its various applications. Images acquired by different sensors have significant differences in feature representation due to the different imaging principles. Taking visible and infrared image fusion as an example, visible images contain abundant texture details with high spatial resolution. In contrast, infrared images can obtain clear target contour information according to the principle of thermal radiation, and work well in all day/night and all weather conditions. Most existing methods employ the same feature extraction algorithm to get the feature information from visible and infrared images, ignoring the differences among these images. Thus, this paper proposes what we believe to be a novel fusion method based on a multi-level image decomposition method and deep learning fusion strategy for multi-type images. In image decomposition, we not only utilize a multi-level extended approximate low-rank projection matrix learning decomposition method to extract salient feature information from both visible and infrared images, but also apply a multi-level guide filter decomposition method to obtain texture information in visible images. In image fusion, a novel fusion strategy based on a pretrained ResNet50 network is presented to fuse multi-level feature information from both visible and infrared images into corresponding multi-level fused feature information, so as to improve the quality of the final fused image. The proposed method is evaluated subjectively and objectively in a large number of experiments. The experimental results demonstrate that the proposed method exhibits better fusion performance than other existing methods.), Reference(id=1241719298943668431, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2012, volume=null, issue=null, pageStart=3354, pageEnd=3361, url=null, language=null, rfNumber=[5], rfOrder=4, authorNames=Geiger A, Lenz P, Urtasun R, journalName=Proceedings of the 2012 IEEE Conference on Computer Vision and Pattern Recognition, refType=null, unstructuredReference=Geiger A, Lenz P, Urtasun R. Are we ready for autonomous driving? The kitti vision benchmark suite[C]// Proceedings of the 2012 IEEE Conference on Computer Vision and Pattern Recognition. Piscataway: IEEE Press, 2012: 3354-3361., articleTitle=Are we ready for autonomous driving? The kitti vision benchmark suite, refAbstract=null), Reference(id=1241719299056914642, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=10.1109/LRA.2021.3110372, pmid=null, pmcid=null, year=2021, volume=6, issue=4, pageStart=8458, pageEnd=8465, url=https://ieeexplore.ieee.org/document/9531543/, language=null, rfNumber=[6], rfOrder=5, authorNames=Zheng X, Zhu J, journalName=IEEE Robotics and Automation Letters, refType=null, unstructuredReference=Zheng X, Zhu J. Efficient LiDAR odometry for autonomous driving[J]. IEEE Robotics and Automation Letters, 2021, 6(4): 8458-8465., articleTitle=Efficient LiDAR odometry for autonomous driving, refAbstract=null), Reference(id=1241719300545892565, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2020, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[7], rfOrder=6, authorNames=null, journalName=CCF 2019—2020 中国计算机科学技术发展报告, refType=null, unstructuredReference=中国计算机学会. CCF 2019—2020 中国计算机科学技术发展报告[M]. 北京: 机械工业出版社, 2020., articleTitle=null, refAbstract=null), Reference(id=1241719300654944474, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=10.1007/s11390-020-0546-7, pmid=null, pmcid=null, year=2020, volume=35, issue=6, pageStart=1365, pageEnd=1381, url=null, language=null, rfNumber=[8], rfOrder=7, authorNames=Liu W W, Song F, Zhang T H R, journalName=Journal of Computer Science and Technology, refType=null, unstructuredReference=Liu W W, Song F, Zhang T H R, et al. Verifying ReLU neural networks from a model checking perspective[J]. Journal of Computer Science and Technology, 2020, 35(6): 1365-1381., articleTitle=Verifying ReLU neural networks from a model checking perspective, refAbstract=null), Reference(id=1241719300743024862, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2022, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[9], rfOrder=8, authorNames=Liang Z, Ren D, Liu W, journalName=Safety verification for neural networks based on set-boundary analysis[DB/OL]. arXiv preprint: 2210.04175, refType=null, unstructuredReference=Liang Z, Ren D, Liu W, et al. Safety verification for neural networks based on set-boundary analysis[DB/OL]. arXiv preprint: 2210.04175, 2022., articleTitle=null, refAbstract=null), Reference(id=1241719300814328033, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2018, volume=null, issue=null, pageStart=3, pageEnd=18, url=null, language=null, rfNumber=[10], rfOrder=9, authorNames=Gehr T, Mirman M, Drachsler-Cohen D, journalName=Proceedings of the 2018 IEEE Symposium on Security and Privacy, refType=null, unstructuredReference=Gehr T, Mirman M, Drachsler-Cohen D, et al. AI2: Safety and robustness certification of neural networks with abstract interpretation[C]// Proceedings of the 2018 IEEE Symposium on Security and Privacy. Piscataway: IEEE Press, 2018: 3-18., articleTitle=AI2: Safety and robustness certification of neural networks with abstract interpretation, refAbstract=null), Reference(id=1241719300873048291, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2017, volume=null, issue=null, pageStart=97, pageEnd=117, url=null, language=null, rfNumber=[11], rfOrder=10, authorNames=Katz G, Barrett C, Dill D L, journalName=Majumdar R, Kunčak V.Proceedings of the 29th International Conference on Computer Aided Verification, refType=null, unstructuredReference=Katz G, Barrett C, Dill D L, et al. Reluplex: An efficient SMT solver for verifying deep neural networks[C]// Majumdar R, Kunčak V.Proceedings of the 29th International Conference on Computer Aided Verification. Cham: Springer, 2017: 97-117., articleTitle=Reluplex: An efficient SMT solver for verifying deep neural networks, refAbstract=null), Reference(id=1241719300927574246, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2020, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[12], rfOrder=11, authorNames=邱锡鹏, journalName=神经网络与深度学习, refType=null, unstructuredReference=邱锡鹏. 神经网络与深度学习[M]. 北京: 机械工业出版社, 2020., articleTitle=null, refAbstract=null), Reference(id=1241719300990488808, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2022, volume=null, issue=null, pageStart=219, pageEnd=231, url=null, language=null, rfNumber=[13], rfOrder=12, authorNames=Casadio M, Komendantskaya E, Daggitt M L, journalName=Shoham S, Vizel Y. Proceedings of the 34th International Conference on Computer Aided Verification, refType=null, unstructuredReference=Casadio M, Komendantskaya E, Daggitt M L, et al. Neural network robustness as a verification property: A principled case study[C]// Shoham S, Vizel Y. Proceedings of the 34th International Conference on Computer Aided Verification. Cham: Springer, 2022: 219-231., articleTitle=Neural network robustness as a verification property: A principled case study, refAbstract=null), Reference(id=1241719301057597674, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2017, volume=null, issue=null, pageStart=269, pageEnd=286, url=null, language=null, rfNumber=[14], rfOrder=13, authorNames=Ehlers R, journalName=D’Souza D, Kumar K N. Proceedings of the 15th International Symposium on Automated Technology for Verification and Analysis, refType=null, unstructuredReference=Ehlers R. Formal verification of piece-wise linear feed-forward neural networks[C]// D’Souza D, Kumar K N. Proceedings of the 15th International Symposium on Automated Technology for Verification and Analysis. Cham: Springer, 2017: 269-286., articleTitle=Formal verification of piece-wise linear feed-forward neural networks, refAbstract=null), Reference(id=1241719301120512236, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2017, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[15], rfOrder=14, authorNames=Lomuscio A, Maganti L, journalName=An approach to reachability analysis for feed-forward ReLU neural networks[DB/OL]. arXiv preprint: 1706.07351, refType=null, unstructuredReference=Lomuscio A, Maganti L. An approach to reachability analysis for feed-forward ReLU neural networks[DB/OL]. arXiv preprint: 1706.07351, 2017., articleTitle=null, refAbstract=null), Reference(id=1241719301196009711, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2018, volume=31, issue=null, pageStart=10825, pageEnd=10836, url=null, language=null, rfNumber=[16], rfOrder=15, authorNames=Singh G, Gehr T, Mirman M, journalName=Advances in Neural Information Processing Systems, refType=null, unstructuredReference=Singh G, Gehr T, Mirman M, et al. Fast and effective robustness certification[J]. Advances in Neural Information Processing Systems, 2018, 31: 10825-10836., articleTitle=Fast and effective robustness certification, refAbstract=null), Reference(id=1241719301258924274, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2022, volume=null, issue=null, pageStart=221, pageEnd=236, url=null, language=null, rfNumber=[17], rfOrder=16, authorNames=Yang X, Yamaguchi T, Tran H D, journalName=Bogomolov S, Parker D. Proceedings of the 20th International Conference on Formal Modeling and Analysis of Timed Systems, refType=null, unstructuredReference=Yang X, Yamaguchi T, Tran H D, et al. Neural network repair with reachability analysis[C]// Bogomolov S, Parker D. Proceedings of the 20th International Conference on Formal Modeling and Analysis of Timed Systems. Cham: Springer, 2022: 221-236., articleTitle=Neural network repair with reachability analysis, refAbstract=null), Reference(id=1241719301321838837, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2021, volume=null, issue=null, pageStart=3, pageEnd=25, url=null, language=null, rfNumber=[18], rfOrder=17, authorNames=Usman M, Gopinath D, Sun Y, journalName=Silva A, Leino K R M.Proceedings of the 33rd International Conference on Computer Aided Verification, refType=null, unstructuredReference=Usman M, Gopinath D, Sun Y, et al. NN repair: Constraint-based repair of neural network classifiers[C]// Silva A, Leino K R M.Proceedings of the 33rd International Conference on Computer Aided Verification. Cham: Springer, 2021: 3-25., articleTitle=NN repair: Constraint-based repair of neural network classifiers, refAbstract=null), Reference(id=1241719301397336312, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2022, volume=null, issue=null, pageStart=338, pageEnd=349, url=null, language=null, rfNumber=[19], rfOrder=18, authorNames=Sun B, Sun J, Pham L H, journalName=Proceedings of the 2022 IEEE/ACM 44th International Conference on Software Engineering, refType=null, unstructuredReference=Sun B, Sun J, Pham L H, et al. Causality-based neural network repair[C]// Proceedings of the 2022 IEEE/ACM 44th International Conference on Software Engineering. Piscataway: IEEE Press, 2022: 338-349., articleTitle=Causality-based neural network repair, refAbstract=null), Reference(id=1241719301590274300, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=10.1186/s40537-018-0162-3, pmid=null, pmcid=null, year=2019, volume=6, issue=1, pageStart=1, pageEnd=48, url=null, language=null, rfNumber=[20], rfOrder=19, authorNames=Shorten C, Khoshgoftaar T M, journalName=Journal of Big Data, refType=null, unstructuredReference=Shorten C, Khoshgoftaar T M. A survey on image data augmentation for deep learning[J]. Journal of Big Data, 2019, 6(1): 1-48., articleTitle=A survey on image data augmentation for deep learning, refAbstract=null), Reference(id=1241719301695131903, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2014, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[21], rfOrder=20, authorNames=Goodfellow I J, Shlens J, Szegedy C, journalName=Explaining and harnessing adversarial examples[DB/OL]. arXiv preprint: 1412.6572, refType=null, unstructuredReference=Goodfellow I J, Shlens J, Szegedy C. Explaining and harnessing adversarial examples[DB/OL]. arXiv preprint: 1412.6572, 2014., articleTitle=null, refAbstract=null), Reference(id=1241719301766435073, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2017, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[22], rfOrder=21, authorNames=Madry A, Makelov A, Schmidt L, journalName=Towards deep learning models resistant to adversarial attacks[DB/OL]. arXiv preprint: 1706.06083, refType=null, unstructuredReference=Madry A, Makelov A, Schmidt L, et al. Towards deep learning models resistant to adversarial attacks[DB/OL]. arXiv preprint: 1706.06083, 2017., articleTitle=null, refAbstract=null), Reference(id=1241719301862904068, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2016, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[23], rfOrder=22, authorNames=Kurakin A, Goodfellow I, Bengio S, journalName=Adversarial machine learning at scale[DB/OL]. arXiv preprint: 1611.01236, refType=null, unstructuredReference=Kurakin A, Goodfellow I, Bengio S. Adversarial machine learning at scale[DB/OL]. arXiv preprint: 1611.01236, 2016., articleTitle=null, refAbstract=null), Reference(id=1241719301950984455, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2018, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[24], rfOrder=23, authorNames=Tsipras D, Santurkar S, Engstrom L, journalName=Robustness may be at odds with accuracy[DB/OL]. arXiv preprint: 1805.12152, refType=null, unstructuredReference=Tsipras D, Santurkar S, Engstrom L, et al. Robustness may be at odds with accuracy[DB/OL]. arXiv preprint: 1805.12152, 2018., articleTitle=null, refAbstract=null), Reference(id=1241719302060036362, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2019, volume=null, issue=null, pageStart=7472, pageEnd=7482, url=null, language=null, rfNumber=[25], rfOrder=24, authorNames=Zhang H, Yu Y, Jiao J, journalName=Proceedings of the 36th International Conference on Machine Learning, refType=null, unstructuredReference=Zhang H, Yu Y, Jiao J, et al. Theoretically principled trade-off between robustness and accuracy[C]// Proceedings of the 36th International Conference on Machine Learning. New York: PMLR, 2019: 7472-7482., articleTitle=Theoretically principled trade-off between robustness and accuracy, refAbstract=null), Reference(id=1241719302127145228, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2018, volume=null, issue=null, pageStart=3578, pageEnd=3586, url=null, language=null, rfNumber=[26], rfOrder=25, authorNames=Mirman M, Gehr T, Vechev M, journalName=Proceedings of the 35th International Conference on Machine Learning, refType=null, unstructuredReference=Mirman M, Gehr T, Vechev M. Differentiable abstract interpretation for provably robust neural networks[C]// Proceedings of the 35th International Conference on Machine Learning. New York: PMLR, 2018: 3578-3586., articleTitle=Differentiable abstract interpretation for provably robust neural networks, refAbstract=null), Reference(id=1241719302227808528, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2018, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[27], rfOrder=26, authorNames=Gowal S, Dvijotham K, Stanforth R, journalName=On the effectiveness of interval bound propagation for training verifiably robust models[DB/OL]. arXiv preprint: 1810.12715, refType=null, unstructuredReference=Gowal S, Dvijotham K, Stanforth R, et al. On the effectiveness of interval bound propagation for training verifiably robust models[DB/OL]. arXiv preprint: 1810.12715, 2018., articleTitle=null, refAbstract=null), Reference(id=1241719302378803476, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2019, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[28], rfOrder=27, authorNames=Zhang H, Chen H, Xiao C, journalName=Towards stable and efficient training of verifiably robust neural networks[DB/OL]. arXiv preprint: 1906.06316, refType=null, unstructuredReference=Zhang H, Chen H, Xiao C, et al. Towards stable and efficient training of verifiably robust neural networks[DB/OL]. arXiv preprint: 1906.06316, 2019., articleTitle=null, refAbstract=null), Reference(id=1241719302479466774, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2019, volume=32, issue=null, pageStart=11423, pageEnd=11434, url=null, language=null, rfNumber=[29], rfOrder=28, authorNames=Fazlyab M, Robey A, Hassani H, journalName=Advances in Neural Information Processing Systems, refType=null, unstructuredReference=Fazlyab M, Robey A, Hassani H, et al. Efficient and accurate estimation of lipschitz constants for deep neural networks[J]. Advances in Neural Information Processing Systems, 2019, 32: 11423-11434., articleTitle=Efficient and accurate estimation of lipschitz constants for deep neural networks, refAbstract=null), Reference(id=1241719302563352857, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=10.1109/LCSYS.2021.3050444, pmid=null, pmcid=null, year=2021, volume=6, issue=null, pageStart=121, pageEnd=126, url=https://ieeexplore.ieee.org/document/9319198/, language=null, rfNumber=[30], rfOrder=29, authorNames=Pauli P, Koch A, Berberich J, journalName=IEEE Control Systems Letters, refType=null, unstructuredReference=Pauli P, Koch A, Berberich J, et al. Training robust neural networks using Lipschitz bounds[J]. IEEE Control Systems Letters, 2021, 6: 121-126., articleTitle=Training robust neural networks using Lipschitz bounds, refAbstract=null), Reference(id=1241719302617878812, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=10.1007/s10994-020-05929-w, pmid=null, pmcid=null, year=2021, volume=110, issue=2, pageStart=393, pageEnd=416, url=null, language=null, rfNumber=[31], rfOrder=30, authorNames=Gouk H, Frank E, Pfahringer B, journalName=Machine Learning, refType=null, unstructuredReference=Gouk H, Frank E, Pfahringer B, et al. Regularisation of neural networks by enforcing Lipschitz continuity[J]. Machine Learning, 2021, 110(2): 393-416., articleTitle=Regularisation of neural networks by enforcing Lipschitz continuity, refAbstract=We investigate the effect of explicitly enforcing the Lipschitz continuity of neural networks with respect to their inputs. To this end, we provide a simple technique for computing an upper bound to the Lipschitz constant—for multiple p-norms—of a feed forward neural network composed of commonly used layer types. Our technique is then used to formulate training a neural network with a bounded Lipschitz constant as a constrained optimisation problem that can be solved using projected stochastic gradient methods. Our evaluation study shows that the performance of the resulting models exceeds that of models trained with other common regularisers. We also provide evidence that the hyperparameters are intuitive to tune, demonstrate how the choice of norm for computing the Lipschitz constant impacts the resulting model, and show that the performance gains provided by our method are particularly noticeable when only a small amount of training data is available.), Reference(id=1241719302693376286, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2021, volume=null, issue=null, pageStart=6212, pageEnd=6222, url=null, language=null, rfNumber=[32], rfOrder=31, authorNames=Leino K, Wang Z, Fredrikson M, journalName=Proceedings of the 38th International Conference on Machine Learning, refType=null, unstructuredReference=Leino K, Wang Z, Fredrikson M. Globally-robust neural networks[C]// Proceedings of the 38th International Conference on Machine Learning. New York: PMLR, 2021: 6212-6222., articleTitle=Globally-robust neural networks, refAbstract=null), Reference(id=1241719302756290848, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2019, volume=3(POPL), issue=null, pageStart=1, pageEnd=30, url=null, language=null, rfNumber=[33], rfOrder=32, authorNames=Singh G, Gehr T, Püschel M, journalName=Proceedings of the ACM on Programming Languages, refType=null, unstructuredReference=Singh G, Gehr T, Püschel M, et al. An abstract domain for certifying neural networks[J]. Proceedings of the ACM on Programming Languages, 2019, 3(POPL): 1-30., articleTitle=An abstract domain for certifying neural networks, refAbstract=null), Reference(id=1241719302823399715, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2019, volume=32, issue=null, pageStart=15287, pageEnd=15297, url=null, language=null, rfNumber=[34], rfOrder=33, authorNames=Balunovic M, Baader M, Singh G, journalName=Advances in Neural Information Processing Systems, refType=null, unstructuredReference=Balunovic M, Baader M, Singh G, et al. Certifying geometric robustness of neural networks[J]. Advances in Neural Information Processing Systems, 2019, 32: 15287-15297., articleTitle=Certifying geometric robustness of neural networks, refAbstract=null), Reference(id=1241719302898897190, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2018, volume=null, issue=null, pageStart=631, pageEnd=648, url=null, language=null, rfNumber=[35], rfOrder=34, authorNames=Su D, Zhang H, Chen H, journalName=Farrari V, Hebert M, Sminchisescu C, et al.Proceedings of the 15th European Conference on Computer Vision. Cham: Springer, refType=null, unstructuredReference=Su D, Zhang H, Chen H, et al. Is robustness the cost of accuracy? A comprehensive study on the robustness of 18 deep image classification models[C]// Farrari V, Hebert M, Sminchisescu C, et al.Proceedings of the 15th European Conference on Computer Vision. Cham: Springer, 2018: 631-648., articleTitle=Is robustness the cost of accuracy? A comprehensive study on the robustness of 18 deep image classification models, refAbstract=null), Reference(id=1241719302974394665, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2019, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[36], rfOrder=35, authorNames=Xie C, Yuille A, journalName=Intriguing properties of adversarial training at scale[DB/OL]. arXiv preprint: 1906.03787, refType=null, unstructuredReference=Xie C, Yuille A, Intriguing properties of adversarial training at scale[DB/OL]. arXiv preprint: 1906.03787, 2019., articleTitle=null, refAbstract=null), Reference(id=1241719303037309228, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2020, volume=null, issue=null, pageStart=631, pageEnd=640, url=null, language=null, rfNumber=[37], rfOrder=36, authorNames=Guo M, Yang Y, Xu R, journalName=Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, refType=null, unstructuredReference=Guo M, Yang Y, Xu R, et al. When NAS meets robustness: In search of robust architectures against adversarial attacks[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. Piscataway: IEEE Press, 2020: 631-640., articleTitle=When NAS meets robustness: In search of robust architectures against adversarial attacks, refAbstract=null), Reference(id=1241719303112806703, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2018, volume=null, issue=null, pageStart=550, pageEnd=559, url=null, language=null, rfNumber=[38], rfOrder=37, authorNames=Bender G, Kindermans P J, Zoph B, journalName=Proceedings of the 35th International Conference on Machine Learning, refType=null, unstructuredReference=Bender G, Kindermans P J, Zoph B, et al. Understanding and simplifying one-shot architecture search[C]// Proceedings of the 35th International Conference on Machine Learning. New York: PMLR, 2018: 550-559., articleTitle=Understanding and simplifying one-shot architecture search, refAbstract=null), Reference(id=1241719303179915570, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2019, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[39], rfOrder=38, authorNames=Cai H, Gan C, Wang T, journalName=Once-for-all: Train one network and specialize it for efficient deployment[DB/OL]. arXiv preprint: 1908.09791, refType=null, unstructuredReference=Cai H, Gan C, Wang T, et al. Once-for-all: Train one network and specialize it for efficient deployment[DB/OL]. arXiv preprint: 1908.09791, 2019., articleTitle=null, refAbstract=null), Reference(id=1241719303238635829, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2018, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[40], rfOrder=39, authorNames=Xiao K Y, Tjeng V, Shafiullah N M, journalName=Training for faster adversarial robustness verification via inducing ReLU stability[DB/OL]. arXiv preprint: 1809.03008, refType=null, unstructuredReference=Xiao K Y, Tjeng V, Shafiullah N M, et al. Training for faster adversarial robustness verification via inducing ReLU stability[DB/OL]. arXiv preprint: 1809.03008, 2018., articleTitle=null, refAbstract=null), Reference(id=1241719303301550392, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, doi=null, pmid=null, pmcid=null, year=2018, volume=null, issue=null, pageStart=null, pageEnd=null, url=null, language=null, rfNumber=[41], rfOrder=40, authorNames=Dvijotham K, Gowal S, Stanforth R, journalName=Training verified learners with learned verifiers[DB/OL]. arXiv preprint: 1805.10265, refType=null, unstructuredReference=Dvijotham K, Gowal S, Stanforth R, et al. Training verified learners with learned verifiers[DB/OL]. arXiv preprint: 1805.10265, 2018., articleTitle=null, refAbstract=null)], funds=[Fund(id=1241719298360660150, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, awardId=61872371, language=CN, fundingSource=国家自然科学基金(61872371), fundOrder=null, country=null), Fund(id=1241719298423574712, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, awardId=61836005, language=CN, fundingSource=国家自然科学基金(61836005), fundOrder=null, country=null), Fund(id=1241719298490683580, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, awardId=62032024, language=CN, fundingSource=国家自然科学基金(62032024), fundOrder=null, country=null)], companyList=[AuthorCompany(id=1241719293860171852, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719293868560461, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719293860171852, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=1. Institute of Quantum Information & State Key Laboratory of High Performance Computing, National University of Defense Technology, Changsha 410073, China), AuthorCompanyExt(id=1241719293885337679, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719293860171852, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=1.国防科技大学量子信息研究所兼高性能计算国家重点实验室,长沙 410073)]), AuthorCompany(id=1241719293956640849, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719293965029458, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719293956640849, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=2. College of Computer Science and Technology, National University of Defense Technology, Changsha 410073, China), AuthorCompanyExt(id=1241719293973418067, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719293956640849, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=2.国防科技大学计算机学院,长沙 410073)]), AuthorCompany(id=1241719294053109845, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719294061498454, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294053109845, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=3. State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China), AuthorCompanyExt(id=1241719294069887063, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294053109845, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=3.中国科学院软件研究所计算机科学国家重点实验室,北京 100190)]), AuthorCompany(id=1241719294141190232, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, xref=null, ext=[AuthorCompanyExt(id=1241719294149578841, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294141190232, language=EN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=4. School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing 100190, China), AuthorCompanyExt(id=1241719294157967450, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, companyId=1241719294141190232, language=CN, country=null, province=null, city=null, postcode=null, companyName=null, departmentName=null, remark=4.中国科学院大学计算机科学与技术学院,北京 100190)])], figs=[ArticleFig(id=1241719298033504428, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, language=EN, label=null, caption=null, figureFileSmall=null, figureFileBig=null, tableContent=
类别 定义 应用场景 可解释性 满足难度
分类鲁棒性 正确分类的样本经过扰动后仍可被神经网络正确分类 分类神经网络 容易
标准鲁棒性 输入扰动后,网络输出的变化范围在用户指定的范围内 一般神经网络 一般
利普希茨鲁棒性 神经网络输出的变化范围与输入的扰动范围存在常数约束 一般神经网络 困难
), ArticleFig(id=1241719298096418991, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, language=CN, label=表1, caption=

各种鲁棒性比较

, figureFileSmall=null, figureFileBig=null, tableContent=
类别 定义 应用场景 可解释性 满足难度
分类鲁棒性 正确分类的样本经过扰动后仍可被神经网络正确分类 分类神经网络 容易
标准鲁棒性 输入扰动后,网络输出的变化范围在用户指定的范围内 一般神经网络 一般
利普希茨鲁棒性 神经网络输出的变化范围与输入的扰动范围存在常数约束 一般神经网络 困难
), ArticleFig(id=1241719298163527858, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, language=EN, label=null, caption=null, figureFileSmall=null, figureFileBig=null, tableContent=
方法 核心思想 训练要素 适用性 实际效果 方法评价
基于数据增强训练 采样 数据集 简单易行,但采样得到的对抗样本比例低,该方法实际可行性差
基于攻击样本训练 网络攻击 数据集 一般 更高效地寻找对抗样本,但需要的采样(迭代)次数多,效率较低
基于网络验证训练 边界过近似 损失函数 训练过程同时优化网络准确性和最差鲁棒性违背情况,可行性强
利普希茨鲁棒性训练 网络参数约束 损失函数 一般 针对利普希茨鲁棒性,损失函数添加正则化项约束利普希茨常数
), ArticleFig(id=1241719298218053812, tenantId=1146029695717560320, journalId=1146032081894723586, articleId=1241719282455868370, language=CN, label=表2, caption=

各种鲁棒神经网络训练方法比较

, figureFileSmall=null, figureFileBig=null, tableContent=
方法 核心思想 训练要素 适用性 实际效果 方法评价
基于数据增强训练 采样 数据集 简单易行,但采样得到的对抗样本比例低,该方法实际可行性差
基于攻击样本训练 网络攻击 数据集 一般 更高效地寻找对抗样本,但需要的采样(迭代)次数多,效率较低
基于网络验证训练 边界过近似 损失函数 训练过程同时优化网络准确性和最差鲁棒性违背情况,可行性强
利普希茨鲁棒性训练 网络参数约束 损失函数 一般 针对利普希茨鲁棒性,损失函数添加正则化项约束利普希茨常数
)], attaches=null, journal=Journal(id=1129340393107079197, delFlag=0, nameCn=前瞻科技, nameEn=Science and Technology Foresight, nameHistory1=null, nameHistory2=null, issn=2097-0781, eissn=, cn=10-1786/N, coden=null, periodic=2, language=CN, oaType=null, ccby=null, superviseOffice=null, ownerOffice=null, pubOffice=null, editorOffice=null, officeType=null, aims=null, clcCode=null, officeProv=null, officeCity=null, officeAddr=null, officeZip=null, officeEmail=null, officePhone=null, editDirector=null, officeDirector=null, officeDirectorPhone=null, officeStaffNum=null, officeEmpNum=null, coverPicUrl=ti95jJIJzXaf02YNe1UF2A==, journalPrice=null, startedYear=null, abbrevIsoEn=Sci Technol Fore, journalRemark=null, publicationField=null, createdTime=null, updatedTime=1788948782472, createdBy=null, updatedBy=13041195026, firstLetterCn=Q, firstLetterEn=Q, subjectCode=Multidisciplinary, subjectName=自然科学, subjectCodeEn=Multidisciplinary, subjectNameEn=null, picCn=ti95jJIJzXaf02YNe1UF2A==, picEn=cuGsq8KPhoqtfsQROuZvoQ==, jcr=null, cjcr=null, exts=[JournalExt(id=1304509001228641229, language=CN, name=前瞻科技, nameHistory1=null, nameHistory2=null, managedBy=中国科学技术协会, sponsoredBy=科技导报社, publishedBy=科技导报社, editorOffice=, officeProv=null, officeCity=null, officeAddr=, officeZip=, editDirector=包为民, officeDirector=null, officePhone=null, coverPicUrl=null, journalRemark=《前瞻科技》是由中国科学技术协会主管,科技导报社主办、出版的科技智库型自然科学综合类学术期刊,于2022年创刊。办刊宗旨:紧扣国家科技创新需求,联合全国学会和科技智库机构,汇聚战略科学家、主流智库学者,通过提供战略性、前瞻性、权威性的思想观点和政策建议,为科技管理者和科研管理者供给高质量决策参考。, submitArticleUrl=null, websiteUrl=http://www.qianzhankeji.cn/CN/2097-0781/home.shtml, createdTime=1788948782498, updatedTime=1788948782498, createdBy=13041195026, updatedBy=13041195026, submissionGuidelinesUrl=http://www.qianzhankeji.cn/CN/column/column7.shtml, submissionAuthorUrl=https://qzkjauthor.cast.org.cn/webm/, submissionEditorUrl=https://qzkjeditor.cast.org.cn/webm/, submissionReviewUrl=https://qzkjauthor.cast.org.cn/webm/, submissionCeEditorUrl=https://qzkjeditor.cast.org.cn/webm/, submissionAeEditorUrl=https://qzkjeditor.cast.org.cn/webm/, option={"copyright":""}), JournalExt(id=1304509001270584270, language=EN, name=Science and Technology Foresight, nameHistory1=null, nameHistory2=null, managedBy=China Association for Science and Technology, sponsoredBy=Science and Technology Review Publishing House, publishedBy=Science and Technology Review Publishing House, editorOffice=, officeProv=null, officeCity=null, officeAddr=, officeZip=, editDirector=BAO Weimin, officeDirector=null, officePhone=null, coverPicUrl=null, journalRemark=Science and Technology Foresight is a comprehensive academic journal in natural sciences with a focus on technology think tanks. It is dedicated to publishing reviews and commentaries on research findings related to major national strategic tasks, important areas at the forefront of technology, and key core technologies and aims to promote academic exchange, advance technological progress, and support the high-quality development of China’s economy and society. The regular sections include “Foresight”, “Review and Commentary”, “Focus”, “Forum”, “Culture”, and “Book Review”. Specifically, “Foresight” and “Review and Commentary” are fixed sections, while the others are variable., submitArticleUrl=null, websiteUrl=http://www.qianzhankeji.cn/EN/2097-0781/home.shtml, createdTime=1788948782508, updatedTime=1788948782508, createdBy=13041195026, updatedBy=13041195026, submissionGuidelinesUrl=http://www.qianzhankeji.cn/EN/column/column7.shtml, submissionAuthorUrl=https://qzkjauthor.manuscriptcloud.com/login, submissionEditorUrl=https://qzkjeditor.manuscriptcloud.com/login, submissionReviewUrl=https://qzkjauthor.manuscriptcloud.com/login, submissionCeEditorUrl=https://qzkjeditor.manuscriptcloud.com/login, submissionAeEditorUrl=https://qzkjeditor.manuscriptcloud.com/login, option={"copyright":""})], databaseList=null, tenantJournalId=1146032081894723586, websiteList=[Website(id=1148243202353652128, webName=null, webTitle=null, webDomain=null, webCopyrigh=null, webIpcNo=null, seoTitle=null, seoKeywords=null, seoDescription=null, tenantJournalId=null, journalId=1146032081894723586, journalNameCn=null, journalNameEn=null, grayFlag=null, tenantId=1146029695717560320, platformId=null, journalGroupId=null, journalGroupNameCn=null, journalGroupNameEn=null, type=1, domain=https://castjournals.cast.org.cn/joweb/qzkjold/CN, language=CHT, createTime=1751692112768, createBy=18614031015, updateTime=1776048748052, updateBy=18614031015, name=《前瞻科技》中文站点, tplId=1146099689490845704, title=前瞻科技, delFlag=0, indexPage=/home, props=[WebsiteProps(id=1148618977242275853, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1148243202353652128, code=articleTextType, value=kx, createTime=1751781704483, updateTime=1751781704483, creator=18614031015, updator=18614031015), WebsiteProps(id=1148618977217110026, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1148243202353652128, code=banner, value=null, createTime=1751781704477, updateTime=1751781704477, creator=18614031015, updator=18614031015), WebsiteProps(id=1148618977204527113, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1148243202353652128, code=logo, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic?fileId=skpCN5mVIzgEJbdUXu8/8A==, createTime=1751781704474, updateTime=1751781704474, creator=18614031015, updator=18614031015), WebsiteProps(id=1148618977233887244, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1148243202353652128, code=picServerUrl, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic, createTime=1751781704481, updateTime=1751781704481, creator=18614031015, updator=18614031015), WebsiteProps(id=1148618977225498635, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1148243202353652128, code=staticResourcePath, value=https://castjournals.cast.org.cn/joweb/cast_kjdb_cn_619/, createTime=1751781704479, updateTime=1751781704479, creator=18614031015, updator=18614031015)]), Website(id=1155894377965830154, webName=null, webTitle=null, webDomain=null, webCopyrigh=null, webIpcNo=null, seoTitle=null, seoKeywords=null, seoDescription=null, tenantJournalId=null, journalId=1146032081894723586, journalNameCn=null, journalNameEn=null, grayFlag=null, tenantId=1146029695717560320, platformId=null, journalGroupId=null, journalGroupNameCn=null, journalGroupNameEn=null, type=1, domain=https://castjournals.cast.org.cn/joweb/qzkjold/EN, language=CHT, createTime=1753516295187, createBy=18614031015, updateTime=1776048768686, updateBy=18614031015, name=《前瞻科技》英文站点, tplId=1146101810881728533, title=Science and Technology Foresight, delFlag=0, indexPage=/home, props=[WebsiteProps(id=1155894740970233959, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1155894377965830154, code=articleTextType, value=kx, createTime=1753516381733, updateTime=1753516381733, creator=18614031015, updator=18614031015), WebsiteProps(id=1155894740953456740, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1155894377965830154, code=banner, value=null, createTime=1753516381729, updateTime=1753516381729, creator=18614031015, updator=18614031015), WebsiteProps(id=1155894740945068131, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1155894377965830154, code=logo, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic?fileId=skpCN5mVIzgEJbdUXu8/8A==, createTime=1753516381727, updateTime=1753516381727, creator=18614031015, updator=18614031015), WebsiteProps(id=1155894740966039654, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1155894377965830154, code=picServerUrl, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic, createTime=1753516381732, updateTime=1753516381732, creator=18614031015, updator=18614031015), WebsiteProps(id=1155894740961845349, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1155894377965830154, code=staticResourcePath, value=https://castjournals.cast.org.cn/joweb/cast_kjdb_cn_619/, createTime=1753516381731, updateTime=1753516381731, creator=18614031015, updator=18614031015)]), Website(id=1246151820205146149, webName=null, webTitle=null, webDomain=null, webCopyrigh=null, webIpcNo=null, seoTitle=null, seoKeywords=null, seoDescription=null, tenantJournalId=null, journalId=1146032081894723586, journalNameCn=null, journalNameEn=null, grayFlag=null, tenantId=1146029695717560320, platformId=null, journalGroupId=null, journalGroupNameCn=null, journalGroupNameEn=null, type=1, domain=https://castjournals.cast.org.cn/joweb/qzkj/CN, language=CN, createTime=1775035346323, createBy=18614031015, updateTime=1776149900371, updateBy=18614031015, name=《前瞻科技》中文站点最新, tplId=1246420490248675410, title=前瞻科技, delFlag=0, indexPage=/home, props=[WebsiteProps(id=1246420037846848371, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246151820205146149, code=articleTextType, value=kx, createTime=1775099294387, updateTime=1775099294387, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420037825876848, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246151820205146149, code=banner, value=null, createTime=1775099294382, updateTime=1775099294382, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420037863625590, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246151820205146149, code=grayFlag, value=0, createTime=1775099294391, updateTime=1775099294391, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420037817488239, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246151820205146149, code=logo, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic?fileId=skpCN5mVIzgEJbdUXu8/8A==, createTime=1775099294380, updateTime=1775099294380, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420037876208504, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246151820205146149, code=minRunFlag, value=0, createTime=1775099294394, updateTime=1775099294394, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420037838459762, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246151820205146149, code=picServerUrl, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic, createTime=1775099294385, updateTime=1775099294385, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420037872014199, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246151820205146149, code=silenceFlag, value=0, createTime=1775099294393, updateTime=1775099294393, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420037834265457, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246151820205146149, code=staticResourcePath, value=https://castjournals.cast.org.cn/joweb/cast_qzkj_cn_319/, createTime=1775099294384, updateTime=1775099294384, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420037851042676, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246151820205146149, code=themeColor, value=null, createTime=1775099294388, updateTime=1775099294388, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420037859431285, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246151820205146149, code=themeStyle, value=null, createTime=1775099294390, updateTime=1775099294390, creator=18614031015, updator=18614031015)]), Website(id=1246404284338716725, webName=null, webTitle=null, webDomain=null, webCopyrigh=null, webIpcNo=null, seoTitle=null, seoKeywords=null, seoDescription=null, tenantJournalId=null, journalId=1146032081894723586, journalNameCn=null, journalNameEn=null, grayFlag=null, tenantId=1146029695717560320, platformId=null, journalGroupId=null, journalGroupNameCn=null, journalGroupNameEn=null, type=1, domain=https://castjournals.cast.org.cn/joweb/qzkj/EN, language=EN, createTime=1775095538466, createBy=18614031015, updateTime=1776333732508, updateBy=18614031015, name=《前瞻科技》英文站点最新, tplId=1246420682825945997, title=Science and Technology Foresight, delFlag=0, indexPage=/home, props=[WebsiteProps(id=1246420311713931340, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246404284338716725, code=articleTextType, value=kx, createTime=1775099359682, updateTime=1775099359682, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420311692959817, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246404284338716725, code=banner, value=null, createTime=1775099359677, updateTime=1775099359677, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420311734902863, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246404284338716725, code=grayFlag, value=0, createTime=1775099359687, updateTime=1775099359687, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420311680376904, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246404284338716725, code=logo, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic?fileId=skpCN5mVIzgEJbdUXu8/8A==, createTime=1775099359674, updateTime=1775099359674, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420311747485777, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246404284338716725, code=minRunFlag, value=0, createTime=1775099359690, updateTime=1775099359690, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420311705542731, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246404284338716725, code=picServerUrl, value=https://castjournals.cast.org.cn/joweb/kjdb/CN/file/pic, createTime=1775099359680, updateTime=1775099359680, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420311739097168, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246404284338716725, code=silenceFlag, value=0, createTime=1775099359688, updateTime=1775099359688, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420311697154122, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246404284338716725, code=staticResourcePath, value=https://castjournals.cast.org.cn/joweb/cast_qzkj_cn_319/, createTime=1775099359678, updateTime=1775099359678, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420311718125645, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246404284338716725, code=themeColor, value=null, createTime=1775099359683, updateTime=1775099359683, creator=18614031015, updator=18614031015), WebsiteProps(id=1246420311726514254, tenantId=1146029695717560320, journalId=null, journalGroupId=null, siteId=1246404284338716725, code=themeStyle, value=null, createTime=1775099359685, updateTime=1775099359685, creator=18614031015, updator=18614031015)])], journalTitle=前瞻科技, weixinUrl=null, journalUrl=null, iacademicId=null, status=1, seqNo=null, journalTitleEn=Science and Technology Foresight, journalPhotoCn=ti95jJIJzXaf02YNe1UF2A==, journalPhotoEn=cuGsq8KPhoqtfsQROuZvoQ==, journalFirstLetter=Q, journalRecommend=null, journalNew=null, journalCollection=null, jcrJf=null, cjcrJf=null, jcrJfStr=null, cjcrJfStr=null, submissionFirstDecision=null, sciSubjectClassification=null, casSubjectClassification=null, citeScore=null, totalCitationFrequency=null, icpCode=null, psCode=null, advertisingLicenseCode=null, copyrightInformation=null, country=null, option=, provinceCode=null, provinceName=null, collectFlag=false, interPubPlatform=, interPubPlatformUrl=null), detailUrlCn=https://castjournals.cast.org.cn/joweb/qzkj/CN/10.3981/j.issn.2097-0781.2023.01.006, detailUrlEn=https://castjournals.cast.org.cn/joweb/qzkj/EN/10.3981/j.issn.2097-0781.2023.01.006, pdfUrlCn=https://castjournals.cast.org.cn/joweb/qzkj/CN/PDF/10.3981/j.issn.2097-0781.2023.01.006, pdfUrlEn=https://castjournals.cast.org.cn/joweb/qzkj/EN/PDF/10.3981/j.issn.2097-0781.2023.01.006, aliStartDate=null, aliEndDate=null, collectionFlag=false, citedCount=null, citedUrl=null, previewStatus=0, delFlag=0, hasFullText=1, orderTime=1679241600000, fullTextJson=null, articleText=null, reference=null)
收藏切换
鲁棒神经网络的训练方法研究进展与前景
收藏切换
PDF下载
梁震 1 , 刘万伟 2, , 吴陶然 3, 4 , 任德金 3, 4 , 薛白 3
前瞻科技 | 综述与述评 2023,2(1): 78-89
收起
收藏切换
前瞻科技 | 综述与述评 2023, 2(1): 78-89
鲁棒神经网络的训练方法研究进展与前景
全屏
梁震1 , 刘万伟2, , 吴陶然3, 4, 任德金3, 4, 薛白3
作者信息
  • 1.国防科技大学量子信息研究所兼高性能计算国家重点实验室,长沙 410073
  • 2.国防科技大学计算机学院,长沙 410073
  • 3.中国科学院软件研究所计算机科学国家重点实验室,北京 100190
  • 4.中国科学院大学计算机科学与技术学院,北京 100190
  • 梁震,博士研究生。主要研究方向为AI可解释性与AI形式化验证等。电子信箱:

    刘万伟,教授,中国计算机学会高级会员。主要研究方向为自动机理论、形式化方法、AI形式化验证等。在IEEE Transactions on Sustainable Energy、ACM Transactions on Quantum Computing、ICSE、ASE、CAV、TACAS、IJCAI等期刊/会议发表多篇论文。参与开发的验证工具在TACAS SV-comp比赛中多次获得第一名。电子信箱:

通信作者:

Advances and Prospects of Training Methods for Robust Neural Networks
Zhen LIANG1 , Wanwei LIU2, , Taoran WU3, 4, Dejin REN3, 4, Bai XUE3
Affiliations
  • 1. Institute of Quantum Information & State Key Laboratory of High Performance Computing, National University of Defense Technology, Changsha 410073, China
  • 2. College of Computer Science and Technology, National University of Defense Technology, Changsha 410073, China
  • 3. State Key Laboratory of Computer Science, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
  • 4. School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing 100190, China
出版时间: 2023-03-20 doi: 10.3981/j.issn.2097-0781.2023.01.006
文章导航
收藏切换

近年来,深度神经网络已经发展成为深度学习的重要计算模型,神经网络的鲁棒性对于其在安全攸关领域的部署至关重要。因此,如何训练鲁棒的神经网络是备受学术界和工业界关注的热点问题。文章介绍了目前主流的3类鲁棒神经网络的训练方法,即基于数据增强训练、基于对抗训练和利普希茨鲁棒性训练;并介绍了其各自方法的核心思想、代表性研究工作和适用范围。同时,将近年来的鲁棒神经网络训练方法的优缺点进行比较,对应到神经网络训练的要素上进行深入分析和对照,并对各类训练方法得到的神经网络的鲁棒性的评价指标进行了介绍和比较。最后,分析了目前鲁棒神经网络训练的难点和热点,展望了该领域可能的研究方向,并提出建议。

深度神经网络  /  鲁棒性  /  神经网络训练

In recent years, deep neural networks have developed into important computing models for deep learning, whose robustness is essential for their deployment in safety-critical areas. Therefore, the way to train robust neural networks is a popular issue that has attracted the attention of academia and industry. In this paper, three mainstream classes of training methods for robust neural networks are introduced, i.e., the method based on data enhancement, that based on adversarial training, and the Lipschitz robust training method. Meanwhile, their core ideas, representative work, and the application scope are introduced. Then, the advantages and disadvantages of the training methods in recent years are compared, and in-depth analysis and comparison are carried out when they correspond to key elements in neural network training. The robustness evaluation metrics of neural networks obtained by these training methods are introduced and compared. Finally, hotspots and challenges of robust neural network training are analyzed, and the possible future directions and some suggestions are briefly summarized.

deep neural network  /  robustness  /  neural network training
梁震, 刘万伟, 吴陶然, 任德金, 薛白. 鲁棒神经网络的训练方法研究进展与前景. 前瞻科技, 2023 , 2 (1) : 78 -89 . DOI: 10.3981/j.issn.2097-0781.2023.01.006
Zhen LIANG, Wanwei LIU, Taoran WU, Dejin REN, Bai XUE. Advances and Prospects of Training Methods for Robust Neural Networks[J]. Science and Technology Foresight, 2023 , 2 (1) : 78 -89 . DOI: 10.3981/j.issn.2097-0781.2023.01.006
随着人工智能(Artificial Intelligence, AI)和深度学习(Deep Learning, DL)的不断发展,深度神经网络(Deep Neural Network, DNN)成为深度学习的重要计算模型之一,在越来越多的领域取得了突出乃至超过人类专家的表现,如自然语言处理[1-2]、图像识别与检测[3-4]和车辆自动驾驶[5-6]等。
但是因为神经网络的黑盒性质,其行为缺少必要的形式化保证和可解释性,导致其在众多安全攸关领域的应用和部署受到极大限制,如医学图像识别与疾病诊断、国防安全与武器制导和无人驾驶等。在神经网络部署到这些重要领域之前,研究者需要对它们的一些关键性质进行形式化验证,以避免发生不可估量的财产或生命损失。常见的神经网络的验证性质包括可达性(Reachability)、安全性(Safety)、公平性(Fairness)和鲁棒性(Robustness)等[7]。目前已有很多方法和工具在不同类型的神经网络上对这些性质进行了验证和评估[8-11]
鲁棒性是神经网络的一个重要性质,即网络输入在一定范围扰动时,输出依然可以保持相对稳定。神经网络的鲁棒性验证是具有重要意义的研究问题,与此相对应的,如何在训练过程中增强神经网络的鲁棒性,这也是一个新兴的重要研究领域。本文将这一问题称作“鲁棒神经网络的训练”。基于目前存在的多种主流的神经网络鲁棒性的形式化定义,将分别从数据增强、对抗训练和利普希茨鲁棒性训练3方面对鲁棒神经网络的训练方法进行阐述,比较它们的优势与不足以及相关的网络鲁棒性的评价指标,并对该领域后续的相关研究做出分析和展望。
神经网络的训练可以理解为在一个神经网络模型(Model)上训练一个高度复杂的函数来拟合给定的训练集(Training Set),并且在测试集(Testing Set)上也能有较好的泛化能力[12]。一般来说,训练集用于训练神经网络模型的参数,测试集则用来评估最终模型的泛化能力,但不参与参数调整的过程。一些情况下,还会在网络模型训练过程中单独划分验证集(Validation Set)来进一步调整模型的超参数以及对模型能力进行初步评估。神经网络的训练过程涉及网络模型、数据集(Data Sets)和损失函数(Loss Function),将它们称作神经网络的训练要素。
神经网络通常由1个输入层(Input Layer),1个输出层(Output Layer)和若干隐藏层(Hidden Layer)组成。每个神经网络层都由若干神经元(Neuron)组成。输入层接收神经网络的输入,而后经过隐藏层的传播计算,在输出层输出最终的计算结果。一般地,局部的相邻的2个网络层之间通常可分解为1个仿射变换(Affine Transformation)和1个非线性激活函数(Non-linear Activation Function)。常见激活函数包括Tanh、Sigmoid和ReLU等,激活函数是定义在向量元素上的函数(Element-wise Function)。总而言之,神经网络的训练本质是不断调整网络参数的过程,使得网络模型具有较好的拟合能力和泛化能力。
数据集是神经网络训练的输入。在有监督学习的学习模式下,数据集的数据通常是一个二元组(x,y),其中x为神经网络的输入,y为预期得到的输出。训练过程中,算法根据训练集进行参数更新,然后在测试集上对泛化性能进行测试,判断网络的训练结果和泛化能力。测试集不参与训练过程,即测试数据不会被加入训练数据集更新网络参数,以表明网络没有出现过拟合(Overfitting)和欠拟合(Underfitting)现象[12]
损失函数是衡量神经网络的输出与预期输出之间差距的函数,损失函数越小,说明二者之间的差距越小,即神经网络输出结果与预期输出越相近,神经网络的性能越好,反之亦然。因此,神经网络在训练过程中一般采用梯度下降法,即通过更新网络参数来追求更小的损失函数值。常见的损失函数有均方差(Mean Squared Error, MSE)损失函数,交叉熵(Cross Entropy)损失函数,折页(Hinge Loss)损失函数等。损失函数记作Lossacc,其中acc为准确度Accuracy的缩写,因为传统的损失函数是基于网络输出的拟合能力而设计的,衡量了数据拟合的准确性。
当神经网络完成了训练过程,部署到应用领域之前,需要对网络的行为进行测试和验证,目的在于确保神经网络满足某些特定的性质,尤其是安全攸关领域。神经网络的鲁棒性是这些网络性质中备受关注的一个,其他常见的性质还有可达性、安全性、公平性等。
鲁棒性原指动态系统在一定的参数摄动下,依旧可以表现稳定。神经网络鲁棒性的概念即由此延伸而来,是指将神经网络输入样本在一定范围内扰动而产生的扰动样本作为网络的输入,神经网络依然能够表现稳定,不会因为输入样本的微小扰动而导致网络输出结果急剧变化。相应地,一般把使得神经网络输出结果发生剧烈变化的扰动样本称作对抗样本(Adversarial Sample)。
一般而言,对神经网络输入扰动形成的扰动样本可以通过集合的范数形式进行定义,常见的范数约束包括1-范数,2-范数或者无穷范数等。
根据神经网络不同的具体应用场景,鲁棒性通常有以下3种定义[13]
分类鲁棒性(Classification Robustness)是指对实现分类任务的神经网络而言,输入样本的微小扰动不会导致神经网络的分类结果发生改变。更具体地,正确分类的样本不会因为扰动而被分到其他类别中。
标准鲁棒性(Standard Robustness)是指输入样本在微小扰动下,神经网络的输出也在一个可容忍的微小范围内变化。这个微小范围一般是用户根据先验经验指定的可容忍的干扰样本输出和真实样本输出之间差距的上界。
利普希茨鲁棒性(Lipschitz Robustness)是基于函数的利普希茨连续性提出的,是标准鲁棒性的一种特殊形式。利普希茨连续性是函数的一种重要性质。如果一个函数是全局利普希茨连续的,那么就存在一个非负常数L使得函数值的变化范围在自变量的变化范围的L倍之内,其中最小的L称为该函数的利普希茨常数。在神经网络上扩展利普希茨连续性的概念,即网络在输入样本的微小扰动下,其输出也在一个微小范围内变化,相较于标准鲁棒性,输出的变化范围与输入的扰动范围之间存在常数约束。同样,满足此性质的最小非负常数L称为神经网络的利普希茨常数。
针对以上各种神经网络鲁棒性的定义,表1从定义、应用场景、可解释性和满足难度4方面进行了比较。
表1可以看出,分类鲁棒性在应用场景方面有较强的局限性,只适用于实现分类任务的神经网络,而标准鲁棒性和利普希茨鲁棒性则不受此限制。从可解释性方面看,分类鲁棒性和标准鲁棒性有较强的可解释性,比较符合人们对于神经网络鲁棒性的直观认识和理解,而利普希茨鲁棒性虽然是标准鲁棒性的一种特例,但是将输出的微小扰动和输入的扰动相关联,这使得它的可解释性不如前面两种。从各种鲁棒性的满足难度方面看,一般来说,分类鲁棒性最容易被满足,标准鲁棒性次之,利普希茨鲁棒性最难满足。
从定义看,这3种鲁棒性定义在表达上是相互关联的。标准鲁棒性是对分类鲁棒性一般意义上的推广,利普希茨鲁棒性则是标准鲁棒性的一种特殊形式。因此,神经网络利普希茨鲁棒性的满足在一定程度上会提升网络满足标准鲁棒性的能力,标准鲁棒性的提升也会促进神经网络满足分类鲁棒性。
对于训练好的神经网络,如何验证神经网络是否满足给定的鲁棒性也是极为受关注的研究方向。针对不同类型的神经网络的鲁棒性验证,目前已有众多的工作及研究方法。
基于SMT(Satisfiability Modulo Theories,可满足性模理论)/SAT(Propositional Satisfiability,命题逻辑可满足性)的验证方法是将鲁棒性编码成为逻辑公式,转换为SMT/SAT问题,通过输入已有SMT/SAT求解器得到验证问题的答案,代表性的工作是Reluplex[11]和Planet[14],但是这类方法的可扩展性较差,计算效率较低,不适用于大规模神经网络的验证。
基于混合整数规划的求解方法最早是由Lomuscio和Maganti[15]提出。通过将神经网络的运算过程编码成混合整数规划问题(Mixed Integer Linear Programming, MILP),然后计算得到网络的输出范围,进而验证其鲁棒性。这类方法使用了凸近似,因此在计算精度上略显不足。此外,混合整数规划问题的求解效率也比较低下。
基于抽象解释(Abstract Interpretation)的方法则是通过选择特定的抽象域(如区间(Interval)、多面体(Polytope)和环形胞带(Zonotope)等),设计专门的转换函数来实现激活函数表达能力的上近似,按照网络层的顺序在网络内部依次传播计算抽象域,得到输出结果的抽象域表示的上近似(Over-approximation)。典型的基于抽象解释的工具有AI2[10]、DeepZ[16]等。本文后续所述的基于验证的训练方法也是指基于抽象解释的验证方法,主要是借助于它们计算得到输出层神经元的边界估计。
基于各种鲁棒性的定义以及已有的网络的鲁棒性验证,产生了如何能够提高神经网络的鲁棒性的研究问题,目前主要有2个问题:①采用何种训练方法,可以使训练得到的神经网络有较强的鲁棒性;②如何通过调整训练好的神经网络的参数来提高已经训练好的神经网络的鲁棒性。本文主要关注问题①,即鲁棒神经网络的训练方法,问题②则更多涉及神经网络修复(Neural Network Repair)的研究范畴[17-19]
为了设计一种训练方法,使训练好的神经网络有更好的鲁棒性,通常会对神经网络训练过程的各个要素进行考量和改进,例如对训练过程的数据集和损失函数等进行改造。本文将从数据增强(Data Augmentation)、对抗训练和利普希茨鲁棒性训练这3方面对目前主流的鲁棒神经网络的训练方法进行阐述和总结。
数据增强[20]最开始是作为一种技术手段应用于神经网络的训练过程以解决过拟合问题。神经网络的训练严重依赖于大量数据去学习一个具有极为复杂的函数,以便对训练数据进行完美的建模。然而,不是所有的研究领域(如医学图像分析领域)都有如此大量的数据供训练。数据增强正是为了解决这个问题而被提出的,它可以提高训练数据集的规模和质量,从而可以使用它们构建更好的深度学习模型。在图像识别领域,增强算法包括几何变换、核滤波器、随机擦除等。这些算法提高了模型的性能,并扩展了有限的数据集。
数据增强也是一种在神经网络训练过程中提高鲁棒性的直观方法。这种方法可以自然推广应用到对输入样本的各种变换,如施加噪声、平移、旋转和缩放。为了应用这种方法在训练过程中提升网络的鲁棒性,需要在输入样本进行某种变换的区域内采集训练样本扩充训练集进行训练。常见的采样方式主要是随机采样。由此,数据增强本质上是从可能存在对抗样本的区域中采集新的训练样本对神经网络进行训练。通常采样函数随机均匀采样,也可以依据先验知识设计更好的采样函数。
基于对抗训练的鲁棒神经网络的训练方法可以分为基于攻击样本的和基于网络验证的训练方法。前者结合了数据增强和网络攻击方法,后者则主要依赖神经网络的鲁棒性验证实现。
数据增强是基于采样数据来扩充训练数据集,但是这种采样获得的数据中极少数是真正对于提升网络鲁棒性有用的数据样本,也就是对抗样本,是一种低效的训练方法。此外,通过采样的方式也不可能遍历所有可能的情况。更具体地,因为通常使用的是随机均匀采样,这种“盲目”采集到的样本绝大多数都是神经网络本来就可以正确分类的样本,产生“对抗样本”的概率很低,这对于神经网络鲁棒性的提高贡献有限。
基于此,产生了“有没有高效寻找对抗样本的方法”的问题,基于攻击样本的训练方法应运而生。这类方法的主要思想是基于反例制导(Counterexample Guided)的训练,即通过对神经网络进行某种“攻击”,得到神经网络不能正确分类的样本,也就是对抗样本,加入到训练过程中进行训练,以期在训练过程中提高神经网络的鲁棒性。目前,代表性的基于攻击样本的训练方法主要有FGSM(Fast Gradient Sign Method,快速梯度符号方法)和PGD(Projected Gradient Descent,投影梯度下降)。
FGSM[21]通过计算损失函数Lossacc关于样本的梯度,然后沿着梯度符号所在的方向对输入样本进行小范围的扰动,获得扰动样本。将获得的扰动样本记作FGSM(x),通过向训练集中添加扰动样本获得新的训练集,从而在训练过程中提高神经网络的鲁棒性。
PGD[22]方法是FGSM的一种代表性的变种方法——将FGSM从一步扩展到多步攻击。PGD方法通过多步迭代FGSM获取攻击样本。PGD方法首先在给定的输入样本上添加随机噪声,然后PGD迭代FGSM攻击到达给定次数后使用新的随机噪声重启攻击过程,以提高攻击成功率。将最后一步得到的扰动样本作为攻击样本加入训练集中进行训练。这种多步迭代使得损失函数值在一定范围内变大,也就是网络越难以分辨真实的标签,因此相较于FGSM获得对抗样本的概率更大。其余FGSM方法的变种和进一步的分析可以参考文献[23-25]
虽然基于攻击样本的训练极大地提高了寻找对抗样本的效率和准确性,但是依然无法遍历所有可能的输入样本。或者说,这些方法只是添加个例样本进行训练,没有从全局考虑输入样本的扰动样本,以改进网络的鲁棒性。
基于验证的鲁棒神经网络训练方法则考虑了所有扰动样本的可能情况。基于验证训练的核心思想是构造一个新的损失函数,在最小化原有损失函数Lossacc的同时(保证性能),也考虑最小化扰动范围内的最差违背鲁棒性的可能情况Lossrobust(保证鲁棒性)。此时,损失函数通常是二者的线性组合,其中Lossacc用来刻画训练过程中神经网络的性能得到保证,Lossrobust则在训练过程中对神经网络的鲁棒性进行约束。最终的损失函数是通过系数折中考虑性能损失和鲁棒性损失。
基于边界的验证是一种典型的网络鲁棒性验证方法,会从神经网络的输入层开始传播一个输入区域到输出层,然后获得输出层各个神经元的过近似的上下界。这个上下界是对于整个输入区域的最差情况的一种保守估计。因此,在训练过程中使用这个上下界,改进最差鲁棒性违背情况,从而提高网络的鲁棒性。
DiffAI[26]基于神经网络鲁棒性验证的思路,采用Hybrid Zonotope作为抽象域,通过设计转换函数实现对激活函数隐藏状态或输出层的上近似,进而估计所有可能的扰动样本中的最差违背鲁棒性的情况。通过这种方法可以训练得到较为鲁棒的神经网络,但是因为Hybrid Zonotope集合表示方式在实际计算中效率比较低,所以训练耗时,对于大规模的神经网络受到限制。此外,DiffAI因为网络传播计算Hybrid Zonotope抽象域的精度原因,只考虑了激活函数为ReLU的神经网络,这也使其在实际网络类型中比较受限。
为了缓解DiffAI存在的不足和限制,可以采用较为松弛的验证抽象域,也就是牺牲一部分的计算精度用以换取网络训练效率的提升,而区间就是满足此性质的较好的抽象域候选。
IBP(Interval Bound Propagation,区间边界传播)[27]方法的核心思想是从输入边界,通过区间传播算法得到输出层神经元的输出范围,从而构建训练过程的损失函数。IBP方法首先通过扰动范围约束,确定每一个输入维度的上下界。然后根据前一层的神经元的边界,通过区间算法计算得到后一层的神经元的边界。IBP方法分别为仿射变换和激活函数设计了边界估计函数。获得输出层的边界后,分别从非真实标签神经元的上界中减去真实标签类别所对应的神经元的下界,得到最差情况的验证边界。基于此可以构造鲁棒性损失函数Lossrobust,与准确度损失函数Lossacc的区别在于此时使用的不是网络对单个样本的输出,而是通过区间传播估计到的边界误差,然后通过构造损失函数在训练过程中更新神经网络参数。这种方法虽然在实际的神经网络鲁棒性验证中没有足够的准确度,主要是因为区间传播的计算边界比较粗糙,从而降低了精度。但是在训练神经网络时,能够快速计算出输出神经元的边界,其计算效率高,因而能够应用到大规模神经网络的鲁棒性训练。
CROWN-IBP方法[28]是IBP算法的一种扩展,目的在于弥补IBP计算边界的粗糙,以期取得更好的训练效果。但是与IBP前向传播计算边界不同,CROWN-IBP采用了一种线性凸近似来描述神经网络的行为,借助后向边界传播方法来计算给定输入范围下输出层神经元的边界。采用前向IBP估计边界和CROWN后向估计边界的加权组合作为最终的边界估计,然后构造新的鲁棒性损失函数。因为得到了更为精确的边界估计,所以CROWN-IBP的鲁棒性损失函数也能够更准确地反映鲁棒性。实验结果也表明,CROWN-IBP在训练神经网络鲁棒性方面取得了比IBP更好的结果。
利普希茨鲁棒性训练方法是为了让神经网络满足利普希茨鲁棒性的训练方法。与上面两类训练方法不同,这类鲁棒性训练方法通常是对神经网络参数进行直接约束,即直接添加关于网络参数的正则化项(Regularization Term)进行训练。
LipSDP方法[29]提出了一种对神经网络利普希茨常数进行高效估计的算法。该算法借助于非线性激活函数满足的斜率受限性质,这种性质对于多种激活函数都成立。这种斜率受限性质可以扩展为向量形式,并且改写成增量二次约束问题,文献[29]给出了网络利普希茨连续的充分条件,命名为LipSDP。基于LipSDP,Pauli等[30]进一步完善了LipSDP问题的定义,并且设计了新的损失函数以提升神经网络的利普希茨连续性。
Gouk等[31]利用函数的利普希茨特性提出,如果两个函数都是利普希茨连续的,那么它们的合成函数也是利普希茨连续的,且其利普希茨常数是原来两个函数的利普希茨常数的乘积。基于这个特性,文章提出对每一层在训练过程中设置阈值作为该层理想的利普希茨常数,神经网络的层数固定之后,则最终整个神经网络理想的利普希茨常数也确定了。通过在训练过程中根据原有损失函数对网络参数进行更新之后,增加投影梯度法(Projected Gradient Method, PGM)对参数进一步更新,以更好满足利普希茨鲁棒性。
前文介绍了目前主流的鲁棒神经网络的训练方法,对于一个训练好的神经网络,通常借助以下指标来衡量其鲁棒性,也反映了各种鲁棒性训练方法的性能[13]
用户-对抗样本存在性(User-Adversarial Existence, UAE)是指用户在实际使用神经网络时遇到对抗样本的可能性。对一个神经网络而言,如果用户-对抗样本存在性指标数值越高,那么它的鲁棒性越差。
攻击样本存在性(Attack Sample Existence, ASE)指标是指对于训练好的神经网络,攻击算法成功找到一个对抗样本的概率。对一个神经网络而言,攻击样本存在性指标越高,它的鲁棒性越差。
与前两个指标相比,可验证性(Verifiable Proportion, VP)指标没有那么直接。可验证性是指对于已训练好的网络,对于训练集中的样本,已有的验证方法能够验证鲁棒性成立的样本的比例(通常会给定验证时间)。对一个神经网络而言,可验证性指标越高,很大程度上其鲁棒性也越高,可验证性指标提供了一个网络鲁棒性的评估下界。
基于各种鲁棒神经网络的训练方法和评价指标,以下对各种训练方法的优缺点以及它们之间的区别和联系进行介绍。
表2从核心思想、训练要素、适用性和实际效果4方面比较了各种鲁棒神经网络训练方法之间的区别,简要给出了各种方法的评价。
基于数据增强训练的核心思想是通过采样来扩充训练数据集,可以适用于各种神经网络鲁棒性定义,但是扩充的数据集中真正是对抗样本的比例很小,因此算法效率不能得到保证,在实际训练网络过程中不具备太大的可行性和实用性。
基于攻击样本训练是从攻击神经网络的角度出发来提高采样中对抗样本的比例,适用于各种鲁棒性定义。因为从攻击角度出发,所以数据集扩充采样的目标更为明确,找到对抗样本的可能性也更高,效率得到保证,应用到训练过程中也更容易改进神经网络的鲁棒性。
基于网络验证训练的核心思想在于验证过程(算法)中提供的输入范围的最差违反鲁棒性情况,然后在训练过程中同时优化鲁棒性损失函数。此类算法避免了采样的低效率和随机性,但是因为训练过程要求损失函数的可微性,所以其适用性一般。目前看来,应用基于网络验证的训练方法,对鲁棒性的提升效果最好。
利普希茨鲁棒性训练方法则主要是针对提升利普希茨鲁棒性而设计的,因此其适用范围最小。并且,由于神经网络的利普希茨属性本身在保证网络性能的前提下不容易满足,因此采用这种方法对利普希茨鲁棒性的提升效果不明显。
从各种方法考虑的网络训练要素看,基于数据增强的训练方法和基于攻击样本的训练方法都是扩充训练数据集。因此,基于攻击样本的训练方法也可以被看作数据增强的一种特例——它采用了更有效的采样方式的数据增强。而基于网络验证的训练方法和利普希茨鲁棒性训练方法都是针对损失函数进行修改,但前者是增加神经网络鲁棒性损失项来优化网络参数更新过程,后者则一般是直接增加约束参数的正则化项。
从鲁棒性之间的联系看,因为利普希茨连续性是一种特殊的标准鲁棒性,因此利普希茨训练方法理论上也一定程度改进了神经网络的标准鲁棒性,但实际训练效果一般。同样,标准鲁棒性是相较于分类鲁棒性更为普遍的定义。因此,改进标准鲁棒性的训练方法也同时提高了网络模型的分类鲁棒性。
另外,目前各种鲁棒神经网络训练方法的分类也不唯一。例如,基于攻击样本的训练方法既可以认为是一种特殊的数据增强方法,也可以认为是基于对抗训练的方法,本文采用的是后者。
经过最近几年在鲁棒神经网络训练方面的研究工作,在训练过程中提高神经网络的鲁棒性已经取得了显著的进展。但该领域的相关工作主要是国外的研究成果,国内相关研究比较缺乏,根据目前该领域的研究进展,仍然存在以下主要难点和研究前景。
目前存在多种鲁棒性的定义,包括但不限于文中列举的几种,这导致已有的训练方法的适用范围存在局限。此外,Leino等也形式化了一个全局鲁棒性(Global Robustness)的概念,它捕获了在线的局部鲁棒性的操作属性,同时为鲁棒网络训练提供了一个自然的训练目标。他们通过将有效的全局利普希茨边界纳入网络,构造产生可靠的鲁棒模型[32]。Singh等[33-34]针对图像数据集提出了几何鲁棒性的定义(图像的旋转、缩放等)并给出了神经网络中此类鲁棒性的验证思路,但几何鲁棒的神经网络的训练方法依然是缺少的。
对于各种形式的神经网络鲁棒性定义,如何基于已有鲁棒性的定义,在构建一个统一的鲁棒性定义框架的基础上,进一步研究发展通用的鲁棒神经网络训练方法是未来值得研究的一个关键问题。这种统一的鲁棒性可以是某种形式上的统一定义,具体鲁棒性是统一定义的特殊形式,在这种统一的鲁棒性框架指导下,鲁棒神经网络训练方法的普适性将更强,也更有助于从理论上指导鲁棒神经网络的训练。
目前已有的鲁棒神经网络的训练方法或关注训练样本(数据集),或关注损失函数的构造(或在损失函数中添加正则项)。结合本文提及的网络训练要素,能否设计某种神经网络结构,使得该种网络结构相较于已有的神经网络结构,能够在训练过程中更容易满足鲁棒性,是一个值得讨论的问题。
之前的一些研究工作涉及了鲁棒的神经网络结构[35-36],更系统的工作是香港中文大学多媒体实验室尝试从神经网络结构的角度全面分析、理解神经网络的鲁棒性[37]。该实验室基于One-shot NAS方法[38]搜索并设计了一系列鲁棒的神经网络结构,命名为RobNets。在CIFAR、SVHN、Tiny-ImageNet和Image等数据集上的实验表明了RobNets相比于其他广泛使用的网络结构,在对抗攻击下具有更好的鲁棒性。文献[37]也揭示了一些有价值的观察结果。例如,密集连接的神经网络模型鲁棒性更高,在存储受限的情况下,卷积运算添加到直连边对于提高鲁棒性更有效。
总体来看,鲁棒的神经网络结构是较少研究的领域,目前已有的工作更多的还是基于神经网络结构搜索开展的[39],虽然提供了一些有意义的观测现象,但是对神经网络结构和网络鲁棒性的理论分析和理解的研究是缺乏的,这也是目前亟待研究的问题。
虽然鲁棒神经网络的训练和验证看上去是矛盾的,但是事实上二者却是相互促进的。更精确的验证技巧可能催生更有效的训练方法,更有效的训练方法也极有可能提升验证的精度和效率。因此,后续的研究中,从相互促进的角度改进鲁棒神经网络的训练方法也是一个值得深入探索的问题。
在目前已有的研究工作中,研究者更多关注的是如何训练易于验证(即验证友好)的鲁棒神经网络。美国麻省理工大学团队基于网络验证探索了协同设计的概念,具体目标是训练的神经网络不仅对对抗性扰动具有鲁棒性,而且其鲁棒性可以更容易验证[40]。为此,该团队确定了网络模型的两个关键属性——权值稀疏性和ReLU稳定性。文献[40]证明了仅改善权值稀疏性就已经使计算上难以解决的验证问题变成可处理的问题,而提高ReLU稳定性可以使验证速度得到极大提升。此外,这种方法可以对众多验证方法都是兼容的。类似的概念也应用在文献[41]中,以训练可验证的神经网络满足某些期望的输入-输出属性(如鲁棒性)。核心思想是同时训练两个网络:一个是执行目前任务的预测器网络;另一个是验证器网络,用于计算预测器网络满足被验证属性的程度。这两个网络可以同时训练,以优化数据拟合损失和限制最大违反属性的项的加权组合。
在神经网络训练和验证相互促进的研究中,目前研究者更多关注的是设计新的训练方法以提升网络验证的效率,而验证方法对于训练的指导作用的相关研究相比显得不足。前文介绍的IBP和CROWN-IBP就是网络验证方法应用于网络训练过程的代表性工作,如何将众多的更加复杂精确的网络验证方法高效地应用于网络鲁棒性训练过程,是下一步研究的重要挑战。
目前,鲁棒神经网络的训练方法主要以学术性实验研究为主,因此实验采用的数据集比较简单(如MNIST手写数字数据集、CIFAR-10彩色图像数据集等),训练的神经网络与实际工程中应用的神经网络在规模上仍有差距。鲁棒性训练方法在实际工程所使用的神经网络中依然是缺位的。因此,下一步的研究也应当更加关注如何将实验的显著效果复现到实际应用中。毕竟,提升实际使用网络的鲁棒性是该领域学术研究的终极目标。
为了尽快将学术成果应用到实际的神经网络中,可以首先将目前成熟的鲁棒性神经网络训练方法应用到一般的实际网络中(网络应用场景安全性要求不高),技术成熟之后,逐渐应用到安全性要求较高的领域中,进一步完善训练方法。
神经网络日益成为深度学习中的主要计算模型,在越来越多的领域中取得了卓越表现。神经网络因其固有的黑盒特性,即在网络行为上缺乏必要的可解释性和安全保证,阻碍了它们在安全攸关领域的应用。鲁棒性则是衡量神经网络行为可靠的重要指标之一,描述了当神经网络的输入在一定范围内扰动时,神经网络的输出不会发生急剧变化,其行为依旧可信。
一方面,研究者提出了大量的关于神经网络的鲁棒性验证的方法和工具,取得了不错的验证精度;另一方面,如何训练鲁棒的神经网络也是重要的研究方向。本文对已有的鲁棒神经网络的验证方法进行了阐述,主要包括基于数据增强训练、基于对抗训练和利普希茨鲁棒性训练,列出了主要的神经网络鲁棒性评价指标,并且对已有方法的优缺点进行了比较。最后,给出了目前该研究领域的研究热点与难点。
  • 国家自然科学基金(61872371)
  • 国家自然科学基金(61836005)
  • 国家自然科学基金(62032024)
参考文献 引证文献
排序方式:
[1]
Karch T, Teodorescu L, Hofmann K, et al. Grounding spatio-temporal language with transformers[J]. Advances in Neural Information Processing Systems, 2021, 34: 5236-5249.
[2]
Wang J, Wang K C, Rudzicz F, et al. Grad2Task: Improved few-shot text classification using gradients for task representation[J]. Advances in Neural Information Processing Systems, 2021, 34: 6542-6554.
[3]
Dahnert M, Hou J, Nießner M, et al. Panoptic 3D scene reconstruction from a single RGB image[J]. Advances in Neural Information Processing Systems, 2021, 34: 8282-8293.
[4]
Tian Y, Yang W, Wang J. Image fusion using a multi-level image decomposition and fusion method[J]. Applied Optics, 2021, 60(24): 7466-7479.
[5]
Geiger A, Lenz P, Urtasun R. Are we ready for autonomous driving? The kitti vision benchmark suite[C]// Proceedings of the 2012 IEEE Conference on Computer Vision and Pattern Recognition. Piscataway: IEEE Press, 2012: 3354-3361.
[6]
Zheng X, Zhu J. Efficient LiDAR odometry for autonomous driving[J]. IEEE Robotics and Automation Letters, 2021, 6(4): 8458-8465.
[7]
中国计算机学会. CCF 2019—2020 中国计算机科学技术发展报告[M]. 北京: 机械工业出版社, 2020.
[8]
Liu W W, Song F, Zhang T H R, et al. Verifying ReLU neural networks from a model checking perspective[J]. Journal of Computer Science and Technology, 2020, 35(6): 1365-1381.
[9]
Liang Z, Ren D, Liu W, et al. Safety verification for neural networks based on set-boundary analysis[DB/OL]. arXiv preprint: 2210.04175, 2022.
[10]
Gehr T, Mirman M, Drachsler-Cohen D, et al. AI2: Safety and robustness certification of neural networks with abstract interpretation[C]// Proceedings of the 2018 IEEE Symposium on Security and Privacy. Piscataway: IEEE Press, 2018: 3-18.
[11]
Katz G, Barrett C, Dill D L, et al. Reluplex: An efficient SMT solver for verifying deep neural networks[C]// Majumdar R, Kunčak V.Proceedings of the 29th International Conference on Computer Aided Verification. Cham: Springer, 2017: 97-117.
[12]
邱锡鹏. 神经网络与深度学习[M]. 北京: 机械工业出版社, 2020.
[13]
Casadio M, Komendantskaya E, Daggitt M L, et al. Neural network robustness as a verification property: A principled case study[C]// Shoham S, Vizel Y. Proceedings of the 34th International Conference on Computer Aided Verification. Cham: Springer, 2022: 219-231.
[14]
Ehlers R. Formal verification of piece-wise linear feed-forward neural networks[C]// D’Souza D, Kumar K N. Proceedings of the 15th International Symposium on Automated Technology for Verification and Analysis. Cham: Springer, 2017: 269-286.
[15]
Lomuscio A, Maganti L. An approach to reachability analysis for feed-forward ReLU neural networks[DB/OL]. arXiv preprint: 1706.07351, 2017.
[16]
Singh G, Gehr T, Mirman M, et al. Fast and effective robustness certification[J]. Advances in Neural Information Processing Systems, 2018, 31: 10825-10836.
[17]
Yang X, Yamaguchi T, Tran H D, et al. Neural network repair with reachability analysis[C]// Bogomolov S, Parker D. Proceedings of the 20th International Conference on Formal Modeling and Analysis of Timed Systems. Cham: Springer, 2022: 221-236.
[18]
Usman M, Gopinath D, Sun Y, et al. NN repair: Constraint-based repair of neural network classifiers[C]// Silva A, Leino K R M.Proceedings of the 33rd International Conference on Computer Aided Verification. Cham: Springer, 2021: 3-25.
[19]
Sun B, Sun J, Pham L H, et al. Causality-based neural network repair[C]// Proceedings of the 2022 IEEE/ACM 44th International Conference on Software Engineering. Piscataway: IEEE Press, 2022: 338-349.
[20]
Shorten C, Khoshgoftaar T M. A survey on image data augmentation for deep learning[J]. Journal of Big Data, 2019, 6(1): 1-48.
[21]
Goodfellow I J, Shlens J, Szegedy C. Explaining and harnessing adversarial examples[DB/OL]. arXiv preprint: 1412.6572, 2014.
[22]
Madry A, Makelov A, Schmidt L, et al. Towards deep learning models resistant to adversarial attacks[DB/OL]. arXiv preprint: 1706.06083, 2017.
[23]
Kurakin A, Goodfellow I, Bengio S. Adversarial machine learning at scale[DB/OL]. arXiv preprint: 1611.01236, 2016.
[24]
Tsipras D, Santurkar S, Engstrom L, et al. Robustness may be at odds with accuracy[DB/OL]. arXiv preprint: 1805.12152, 2018.
[25]
Zhang H, Yu Y, Jiao J, et al. Theoretically principled trade-off between robustness and accuracy[C]// Proceedings of the 36th International Conference on Machine Learning. New York: PMLR, 2019: 7472-7482.
[26]
Mirman M, Gehr T, Vechev M. Differentiable abstract interpretation for provably robust neural networks[C]// Proceedings of the 35th International Conference on Machine Learning. New York: PMLR, 2018: 3578-3586.
[27]
Gowal S, Dvijotham K, Stanforth R, et al. On the effectiveness of interval bound propagation for training verifiably robust models[DB/OL]. arXiv preprint: 1810.12715, 2018.
[28]
Zhang H, Chen H, Xiao C, et al. Towards stable and efficient training of verifiably robust neural networks[DB/OL]. arXiv preprint: 1906.06316, 2019.
[29]
Fazlyab M, Robey A, Hassani H, et al. Efficient and accurate estimation of lipschitz constants for deep neural networks[J]. Advances in Neural Information Processing Systems, 2019, 32: 11423-11434.
[30]
Pauli P, Koch A, Berberich J, et al. Training robust neural networks using Lipschitz bounds[J]. IEEE Control Systems Letters, 2021, 6: 121-126.
[31]
Gouk H, Frank E, Pfahringer B, et al. Regularisation of neural networks by enforcing Lipschitz continuity[J]. Machine Learning, 2021, 110(2): 393-416.
[32]
Leino K, Wang Z, Fredrikson M. Globally-robust neural networks[C]// Proceedings of the 38th International Conference on Machine Learning. New York: PMLR, 2021: 6212-6222.
[33]
Singh G, Gehr T, Püschel M, et al. An abstract domain for certifying neural networks[J]. Proceedings of the ACM on Programming Languages, 2019, 3(POPL): 1-30.
[34]
Balunovic M, Baader M, Singh G, et al. Certifying geometric robustness of neural networks[J]. Advances in Neural Information Processing Systems, 2019, 32: 15287-15297.
[35]
Su D, Zhang H, Chen H, et al. Is robustness the cost of accuracy? A comprehensive study on the robustness of 18 deep image classification models[C]// Farrari V, Hebert M, Sminchisescu C, et al.Proceedings of the 15th European Conference on Computer Vision. Cham: Springer, 2018: 631-648.
[36]
Xie C, Yuille A, Intriguing properties of adversarial training at scale[DB/OL]. arXiv preprint: 1906.03787, 2019.
[37]
Guo M, Yang Y, Xu R, et al. When NAS meets robustness: In search of robust architectures against adversarial attacks[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. Piscataway: IEEE Press, 2020: 631-640.
[38]
Bender G, Kindermans P J, Zoph B, et al. Understanding and simplifying one-shot architecture search[C]// Proceedings of the 35th International Conference on Machine Learning. New York: PMLR, 2018: 550-559.
[39]
Cai H, Gan C, Wang T, et al. Once-for-all: Train one network and specialize it for efficient deployment[DB/OL]. arXiv preprint: 1908.09791, 2019.
[40]
Xiao K Y, Tjeng V, Shafiullah N M, et al. Training for faster adversarial robustness verification via inducing ReLU stability[DB/OL]. arXiv preprint: 1809.03008, 2018.
[41]
Dvijotham K, Gowal S, Stanforth R, et al. Training verified learners with learned verifiers[DB/OL]. arXiv preprint: 1805.10265, 2018.
2023年第2卷第1期
PDF下载
2699
1482
引用本文
BibTeX
文章信息
doi: 10.3981/j.issn.2097-0781.2023.01.006
  • 接收时间:2022-12-24
  • 出版时间:2023-03-20
  • 发布时间:2023-03-27
补充材料
相关文章
文章信息
作者
出版历史
  • 收稿日期:2022-12-24
  • 修回日期:2023-02-01
基金
国家自然科学基金(61872371)
国家自然科学基金(61836005)
国家自然科学基金(62032024)
作者信息
    1.国防科技大学量子信息研究所兼高性能计算国家重点实验室,长沙 410073
    2.国防科技大学计算机学院,长沙 410073
    3.中国科学院软件研究所计算机科学国家重点实验室,北京 100190
    4.中国科学院大学计算机科学与技术学院,北京 100190

通讯作者:

参考文献
分享链接
https://castjournals.cast.org.cn/joweb/qzkj/CN/10.3981/j.issn.2097-0781.2023.01.006
分享至
全文二维码

扫描看全文

引用本文
BibTeX
本文的引用情况
表12种不同金属材料的力学参数

Family
属数
Number of
genus
种数
Number of
species
占总种数比例
Percentage of
total species (%)

Genus
种数
Number of
species
占总种数比例
Percentage of total
species (%)
鹅膏菌科Amanitaceae 2 11 5.26 鹅膏菌属 Amanita 10 4.78
小菇科 Mycenaceae 2 12 5.74 丝盖伞属 Inocybe 5 2.39
多孔菌科 Polyporaceae 8 14 6.70 蜡蘑属 Laccaria 5 2.39
红菇科 Russulaceae 3 23 11.00 小皮伞属 Marasmius 6 2.87
小菇属 Mycena 11 5.26
光柄菇属 Pluteus 5 2.39
红菇属 Russula 17 8.13
栓菌属 Trametes 5 2.39
关闭全屏