REVIEW 2 cited by
Orthogonalizing Convolutional Layers with the Cayley Transform
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
abstract
Recent work has highlighted several advantages of enforcing orthogonality in the weight layers of deep networks, such as maintaining the stability of activations, preserving gradient norms, and enhancing adversarial robustness by enforcing low Lipschitz constants. Although numerous methods exist for enforcing the orthogonality of fully-connected layers, those for convolutional layers are more heuristic in nature, often focusing on penalty methods or limited classes of convolutions. In this work, we propose and evaluate an alternative approach to directly parameterize convolutional layers that are constrained to be orthogonal. Specifically, we propose to apply the Cayley transform to a skew-symmetric convolution in the Fourier domain, so that the inverse convolution needed by the Cayley transform can be computed efficiently. We compare our method to previous Lipschitz-constrained and orthogonal convolutional layers and show that it indeed preserves orthogonality to a high degree even for large convolutions. Applied to the problem of certified adversarial robustness, we show that networks incorporating the layer outperform existing deterministic methods for certified defense against $\ell_2$-norm-bounded adversaries, while scaling to larger architectures than previously investigated. Code is available at https://github.com/locuslab/orthogonal-convolutions.
Forward citations
Cited by 2 Pith papers
-
Constrained Optimization on Matrix Lie Groups via Interior-Point Method
A metric-free interior-point optimizer on matrix Lie groups with Lie-algebra Newton steps is claimed to converge quadratically and outperform Riemannian IPMs on SO(7) and SL(7) benchmarks.
-
Inference Privacy: Properties and Mechanisms
Inference Privacy requires that a model's output distributions for any two inputs within a chosen radius alpha are almost identical, and it is implemented by calibrating input or output noise with standard differentia...
Discussion (0). Continue with ORCID to comment.