{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/towards-certifying-ell-infty-robustness-using-1","title":"Towards Certifying L-infinity Robustness using Neural Networks with L-inf-dist Neurons","arxiv_id":"2102.05363","date":"2021-02-10","proceeding":null,"authors":["Bohang Zhang","Tianle Cai","Zhou Lu","Di He","LiWei Wang"],"abstract":"It is well-known that standard neural networks, even with a high classification accuracy, are vulnerable to small $\\ell_\\infty$-norm bounded adversarial perturbations. Although many attempts have been made, most previous works either can only provide empirical verification of the defense to a particular attack method, or can only develop a certified guarantee of the model robustness in limited scenarios. In this paper, we seek for a new approach to develop a theoretically principled neural network that inherently resists $\\ell_\\infty$ perturbations. In particular, we design a novel neuron that uses $\\ell_\\infty$-distance as its basic operation (which we call $\\ell_\\infty$-dist neuron), and show that any neural network constructed with $\\ell_\\infty$-dist neurons (called $\\ell_{\\infty}$-dist net) is naturally a 1-Lipschitz function with respect to $\\ell_\\infty$-norm. This directly provides a rigorous guarantee of the certified robustness based on the margin of prediction outputs. We then prove that such networks have enough expressive power to approximate any 1-Lipschitz function with robust generalization guarantee. We further provide a holistic training strategy that can greatly alleviate optimization difficulties. Experimental results show that using $\\ell_{\\infty}$-dist nets as basic building blocks, we consistently achieve state-of-the-art performance on commonly used datasets: 93.09% certified accuracy on MNIST ($\\epsilon=0.3$), 35.42% on CIFAR-10 ($\\epsilon=8/255$) and 16.31% on TinyImageNet ($\\epsilon=1/255$).","url_abs":"https://arxiv.org/abs/2102.05363v4","url_pdf":"https://arxiv.org/pdf/2102.05363v4.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"towards-certifying-ell-infty-robustness-using-1","repo_url":"https://github.com/zbh2047/L_inf-dist-net","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}},{"paper_slug":"towards-certifying-ell-infty-robustness-using-1","repo_url":"https://github.com/zbh2047/L_inf-dist-net-v2","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2102.05363","atlas_url":"https://app.syntology.ai/?focus=2102.05363","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}