A study on the uncertainty of convolutional layers in deep neural networks

被引:29
作者
Shen, Haojing [1 ,3 ]
Chen, Sihong [1 ,3 ]
Wang, Ran [2 ,3 ,4 ]
机构
[1] Shenzhen Univ, Coll Comp Sci & Software Engn, Big Data Inst, Shenzhen 518060, Peoples R China
[2] Shenzhen Univ, Coll Math & Stat, Shenzhen 518060, Peoples R China
[3] Shenzhen Univ, Guangdong Key Lab Intelligent Informat Proc, Shenzhen 518060, Peoples R China
[4] Shenzhen Univ, Shenzhen Key Lab Adv Machine Learning & Applicat, Shenzhen 518060, Peoples R China
关键词
Uncertainty; Adversarial training; Convolution; LeNet; Min– Max property;
D O I
10.1007/s13042-021-01278-9
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
This paper shows a Min-Max property existing in the connection weights of the convolutional layers in a neural network structure, i.e., the LeNet. Specifically, the Min-Max property means that, during the back propagation-based training for LeNet, the weights of the convolutional layers will become far away from their centers of intervals, i.e., decreasing to their minimum or increasing to their maximum. From the perspective of uncertainty, we demonstrate that the Min-Max property corresponds to minimizing the fuzziness of the model parameters through a simplified formulation of convolution. It is experimentally confirmed that the model with the Min-Max property has a stronger adversarial robustness, thus this property can be incorporated into the design of loss function. This paper points out a changing tendency of uncertainty in the convolutional layers of LeNet structure, and gives some insights to the interpretability of convolution.
引用
收藏
页码:1853 / 1865
页数:13
相关论文
共 57 条
[31]   DeepFool: a simple and accurate method to fool deep neural networks [J].
Moosavi-Dezfooli, Seyed-Mohsen ;
Fawzi, Alhussein ;
Frossard, Pascal .
2016 IEEE CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2016, :2574-2582
[32]  
Papernot N., 2016, ARXIV161000768
[33]   Distillation as a Defense to Adversarial Perturbations against Deep Neural Networks [J].
Papernot, Nicolas ;
McDaniel, Patrick ;
Wu, Xi ;
Jha, Somesh ;
Swami, Ananthram .
2016 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2016, :582-597
[34]   The Limitations of Deep Learning in Adversarial Settings [J].
Papernot, Nicolas ;
McDaniel, Patrick ;
Jha, Somesh ;
Fredrikson, Matt ;
Celik, Z. Berkay ;
Swami, Ananthram .
1ST IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY, 2016, :372-387
[35]  
Pinto L, 2017, PR MACH LEARN RES, V70
[36]  
Pourpanah F, 2020, ARXIV PREPRINT ARXIV
[37]  
Qin C, 2019, ADV NEUR IN, V32
[38]  
Raghunathan A, 2018, ARXIV180109344
[39]  
Seeger Matthias, 2004, Int J Neural Syst, V14, P69, DOI 10.1142/S0129065704001899
[40]  
Shannon C. E., 2001, ACM SIGMOBILE Mobile Comput. Commun. Rev., V5, P3, DOI [DOI 10.1002/J.1538-7305.1948.TB01338.X, 10.1002/j.1538-7305.1948.tb01338.x]