Abstract

High-dimensional embeddings are often projected via fully connected layers while training neural networks. A major vulnerability that makes neural networks fail to be robust against adversarial attack is their use of overparameterized fully connected layers. We present a dimension reducing layer which preserves high-dimensional neighborhoods across the entire manifold. Atypically, our neighborhood preserving layer operates on non-static high dimensional inputs and can be trained efficiently via gradient descent. Our interest is in developing a trainable manifold representation, whose low-dimensional embeddings can be re-used for other purposes, and in investigating its robustness against adversarial attack.Our layer internally uses nearest-neighbor attractive and repulsive forces to create a low dimensional output representation. We demonstrate a novel neural network architecture which can incorporate such a layer, and also can be trained efficiently. Our theoretical results show why linear layers, which have many parameters, are innately less robust. This is corroborated by experiments on MNIST and CIFAR10 replacing the first fully-connected layer with a neighborhood preserving layer by our proposed model.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.