Sparse Ultrametric Solutions via Replica Symmetry Breaking for Adversarial Defense
摘要
Replica Symmetry Breaking (RSB) provides a powerful framework for analyzing complex systems, including deep neural networks (DNNs), by elucidating their non-convex optimization landscapes. In this study, we apply RSB principles to develop a defense mechanism against generative adversarial attacks on DNNs. Our method employs a specialized quasi-cyclic bipartite graph (QC-LDPC code) with optimized minima structures and integrates compressed sensing techniques to address hierarchical perturbations, all while preserving the integrity of the pretrained network. These adversarial attacks disrupt neural network representations in a manner akin to how perturbations in Random Bond Ising Models (RBIM) impact hierarchical clustering in complex systems. By incorporating temperature-like parameters from RBIM, RSB theory sheds light on the types of energy landscape solutions that can be predicted. Our approach leverages theoretical insights from RBIM and ultrametric distance spectra to construct robust defense strategies, aligned with the Langevin dynamics of adversarial defense. Compared to diffusion purification techniques, our method enhances accuracy by 3.5% under adversarial conditions, reduces computational complexity, and is compatible with low-complexity DNNs such as SqueezeNet, making it well-suited for deployment on edge devices.