资源论文SPAN RECOVERY FOR DEEP NEURAL NETWORKS WITH APPLI -CATIONS TO INPUT OBFUSCATION

SPAN RECOVERY FOR DEEP NEURAL NETWORKS WITH APPLI -CATIONS TO INPUT OBFUSCATION

2019-12-30 | |  72 |   44 |   0

Abstract

The tremendous success of deep neural networks has motivated the need to better understand the fundamental properties of these networks, but many of the theoretical results proposed have only been for shallow networks. In this paper, we study an important primitive for understanding the meaningful input space of a deep network: span recovery. For k < n, let A 图片.png be the innermost weight matrix of an arbitrary feed forward neural network M :图片.png so M (x) can be written as M (x) =图片.png for some network 图片.pngThe goal is then to recover the row span of A given only oracle access to the value of M (x). We show that if M is a multi-layered network with ReLU activation functions, then partial recovery is possible: namely, we can provably recover k/2 linearly independent vectors in the row span of A using poly(n) non-adaptive queries to M (x). Furthermore, if M has differentiable activation functions, we demonstrate that full span recovery is possible even when the output is first passed through a sign or 0/1 thresholding function; in this case our algorithm is adaptive. Empirically, we confirm that full span recovery is not always possible, but only for unrealistically thin layers. For reasonably wide networks, we obtain full span recovery on both random networks and networks trained on MNIST data. Furthermore, we demonstrate the utility of span recovery as an attack by inducing neural networks to misclassify data obfuscated by controlled random noise as sensical inputs.

上一篇:PIECEWISE LINEAR ACTIVATIONS CANSUBSTANTIALLY SHAPE THE LOSS SURFACES OFNEURAL NETWORKS

下一篇:DISTRIBUTIONALLY ROBUST NEURAL NETWORKSFOR GROUP SHIFTS :O NTHE IMPORTANCE OF REG -ULARIZATION FOR WORST-C ASE GENERALIZATION

用户评价
全部评价

热门资源

  • Learning to Predi...

    Much of model-based reinforcement learning invo...

  • Stratified Strate...

    In this paper we introduce Stratified Strategy ...

  • The Variational S...

    Unlike traditional images which do not offer in...

  • A Mathematical Mo...

    Direct democracy, where each voter casts one vo...

  • Rating-Boosted La...

    The performance of a recommendation system reli...