arXiv:cs.LG· V\v{e}ra K\r{u}rkov\'a·· 5 小时前AI 评分38
深度 ReLU 网络鲁棒性的理论下界
Theoretical Lower Bounds on the Robustness of Deep ReLU Networks
AI 导读
一项理论研究为深度 ReLU 网络的局部鲁棒性推导出下界,方法是将高维几何中的测度集中工具与网络输入输出函数所诱导几何结构的新刻画相结合。研究证明,ReLU 网络划分输入空间得到的每个凸多面体区域,其面数至多等于网络单元数,与网络深度或架构无关。分析还表明,随输入维度增加,包含脆弱点的决策边界邻域宽度迅速收缩,而随网络单元数仅呈对数增长。
正文
Abstract:We present a theoretical study of the robustness of parameterized neural networks to random input perturbations. Specifically, we analyze local robustness by quantifying the probability that a random L_2-perturbation of a given input results in a correct classification. For deep ReLU networks, we derive lower bounds on local robustness by combining tools from high-dimensional geometry, in particular concentration of measure, with a new characterization of the geometric structure induced by their input-output functions. We prove that each convex polyhedral region in the partition of the input space induced by a ReLU network has at most as many faces as there are network units, regardless of the network depth or architecture. This geometric property serves as the key ingredient in our robustness analysis. Finally, we analyze how local robustness scales with input dimension and characterize the sets of inputs whose neighborhoods are most likely to contain adversarial examples. We show that the width of decision-boundary neighborhoods containing vulnerable points shrinks rapidly as dimension increases and grows only logarithmically with the number of network units. We also discuss the volume of a set of vulnerable points in terms of approximately space-filling shapes of decision boundaries.
| Comments: | 15 pages, 4 figures |
| Subjects: | Machine Learning (cs.LG); Neural and Evolutionary Computing (cs.NE) |
| MSC classes: | 51, 60 |
| ACM classes: | G.0; G.3 |
| Cite as: | arXiv:2602.18674 [cs.LG] |
| (or arXiv:2602.18674v2 [cs.LG] for this version) | |
| https://doi.org/10.48550/arXiv.2602.18674 arXiv-issued DOI via DataCite |
Submission history
From: Vera Kurkova [view email]
[v1]
Sat, 21 Feb 2026 00:55:47 UTC (52 KB)
[v2]
Fri, 2 Oct 2026 16:39:34 UTC (191 KB)
来源:arXiv:cs.LG · arxiv.org