On robustness of neural ODEs image classifiers

被引:10
|
作者
Cui, Wenjun [1 ]
Zhang, Honglei [1 ]
Chu, Haoyu [1 ]
Hu, Pipi [2 ]
Li, Yidong [1 ]
机构
[1] Beijing Jiaotong Univ, Sch Comp & Informat Technol, Beijing 100044, Peoples R China
[2] Microsoft Res AI4Sci, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
Neural ODEs; Activation functions; Dynamical behavior; Robustness;
D O I
10.1016/j.ins.2023.03.049
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Neural Ordinary Differential Equations (Neural ODEs), as a family of novel deep models, delicately link conventional neural networks and dynamical systems, which bridges the gap between theory and practice. However, they have not made substantial progress on activation functions, and ReLU is always utilized by default. Moreover, the dynamical behavior existing in them becomes more unclear and complicated as training progresses. Fortunately, existing studies have shown that activation functions are essential for Neural ODEs in governing intrinsic dynamics. Motivated by a family of weight functions used to enhance the stability of dynamical systems, we introduce a new activation function named half-Swish to match Neural ODEs. Besides, we explore the effect of evolution time and batch size on Neural ODEs, respectively. Experiments show that our model consistently outperforms Neural ODEs with basic activation functions on robustness both against stochastic noise images and adversarial examples across Fashion-MNIST, CIFAR-10, and CIFAR-100 datasets, which strongly validates the applicability of half-Swish and suggests that half-Swish function plays a positive role in regularizing the dynamic behavior to enhance stability. Meanwhile, our work theoretically provides a prospective framework to choose appropriate activation functions to match neural differential equations.
引用
收藏
页码:576 / 593
页数:18
相关论文
共 50 条
  • [1] Computational Analysis of Robustness in Neural Network Classifiers
    Beckova, Iveta
    Pocos, Stefan
    Farkas, Igor
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING, ICANN 2020, PT I, 2020, 12396 : 65 - 76
  • [2] ROBY: a Tool for Robustness Analysis of Neural Network Classifiers
    Arcaini, Paolo
    Bombarda, Andrea
    Bonfanti, Silvia
    Gargantini, Angelo
    2021 14TH IEEE CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST 2021), 2021, : 442 - 447
  • [3] A Framework for Including Uncertainty in Robustness Evaluation of Bayesian Neural Network Classifiers
    Essbai, Wasim
    Bombarda, Andrea
    Bonfanti, Silvia
    Gargantini, Angelo
    PROCEEDINGS OF THE 2024 IEEE/ACM INTERNATIONAL WORKSHOP ON DEEP LEARNING FOR TESTING AND TESTING FOR DEEP LEARNING, DEEPTEST 2024, 2024, : 25 - 32
  • [4] ROBUSTNESS OF DEEP CONVOLUTIONAL NEURAL NETWORKS FOR IMAGE DEGRADATIONS
    Ghosh, Sanjukta
    Shet, Rohan
    Amon, Peter
    Hutter, Andreas
    Kaup, Andre
    2018 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2018, : 2916 - 2920
  • [5] Dealing with Robustness of Convolutional Neural Networks for Image Classification
    Arcaini, Paolo
    Bombarda, Andrea
    Bonfanti, Silvia
    Gargantini, Angelo
    2020 IEEE INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE TESTING (AITEST), 2020, : 7 - 14
  • [6] Robustness of Biologically Grounded Neural Networks Against Image Perturbations
    Teichmann, Michael
    Larisch, Rene
    Hamker, Fred H.
    ARTIFICIAL NEURAL NETWORKS AND MACHINE LEARNING-ICANN 2024, PT X, 2024, 15025 : 220 - 230
  • [7] Robustness of Sketched Linear Classifiers to Adversarial Attacks
    Mahadevan, Ananth
    Merchant, Arpit
    Wang, Yanhao
    Mathioudakis, Michael
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON INFORMATION AND KNOWLEDGE MANAGEMENT, CIKM 2022, 2022, : 4319 - 4323
  • [8] Evaluating the adversarial robustness of Arabic spam classifiers
    Anwar Alajmi
    Imtiaz Ahmad
    Ameer Mohammed
    Neural Computing and Applications, 2025, 37 (6) : 4323 - 4343
  • [9] Robustness and Transferability of Adversarial Attacks on Different Image Classification Neural Networks
    Smagulova, Kamilya
    Bacha, Lina
    Fouda, Mohammed E.
    Kanj, Rouwaida
    Eltawil, Ahmed
    ELECTRONICS, 2024, 13 (03)
  • [10] Empirical comparison of robustness of classifiers on IR imagery
    Zhang, P
    Peng, J
    Zhang, K
    Sims, SRF
    AUTOMATIC TARGET RECOGNITON XV, 2005, 5807 : 370 - 379