Bayesian Hypernetworks

David Krueger, Chin-Wei Huang, Riashat Islam, Ryan Turner, Alexandre Lacoste, Aaron Courville

Introduction

Simple and powerful techniques for Bayesian inference of deep neural networks’ (DNNs) parameters have the potential to dramatically increase the scope of applications for deep learning techniques. In real-world applications, unanticipated mistakes may be costly and dangerous, whereas anticipating mistakes allows an agent to seek human guidance (as in active learning), engage safe default behavior (such as shutting down), or use a “reject option” in a classification context.

DNNs are typically trained to find the single most likely value of the parameters (the “MAP estimate”), but this approach neglects uncertainty about which parameters are the best (“parameter uncertainty”), which may translate into higher predictive uncertainty when likely parameter values yield highly confident but contradictory predictions. Conversely, Bayesian DNNs model the full posterior distribution of a model’s parameters given the data, and thus provides better calibrated confidence estimates, with corresponding safety benefits (Gal & Ghahramani, 2016; Amodei et al., 2016).While Bayesian deep learning may capture parameter uncertainty, most approaches, including ours, emphatically do not capture uncertainty about which model is correct (e.g., neural net vs decision tree, etc.). Parameter uncertainty is often called “model uncertainty” in the literature, but we prefer our terminology because it emphasizes the existence of further uncertainty about model specification. Maintaining a distribution over parameters is also one of the most effective defenses against adversarial attacks (Carlini & Wagner, 2017).

Techniques for Bayesian DNNs are an active research topic. The most popular approach is variational inference (Blundell et al., 2015; Gal, 2016), which typically restricts the variational posterior to a simple family of distributions, for instance a factorial Gaussian (Blundell et al., 2015; Graves, 2011). Unfortunately, from a safety perspective, variational approximations tend to underestimate uncertainty, by heavily penalizing approximate distributions which place mass in regions where the true posterior has low density. This problem can be exacerbated by using a restricted family of posterior distribution; for instance a unimodal approximate posterior will generally only capture a single mode of the true posterior. With this in mind, we propose learning an extremely flexible and powerful posterior, parametrized by a DNN hh, which we refer to as a Bayesian hypernetwork in reference to Ha et al. (2017).

A Bayesian hypernetwork (BHN) takes random noise ϵ∼N(0,I){\bm{\mathbf{\epsilon}}}\sim\mathcal{N}({\bm{\mathbf{0}}},{\mathbf{I}}) as input and outputs a sample from the approximate posterior q(θ)q({\bm{\mathbf{\theta}}}) for another DNN of interest (the “primary network”). The key insight for building such a model is the use of an invertible hypernet, which enables Monte Carlo estimation of the entropy term −log⁡q(θ){-\log}q({\bm{\mathbf{\theta}}}) in the variational inference training objective.

We begin the paper by reviewing previous work on Bayesian DNNs, and explaining the necessary components of our approach (Section 2). Then we explain how to compose these techniques to yield Bayesian hypernets, as well as design choices which make training BHNs efficient, stable and robust (Section 3). Finally, we present experiments which validate the expressivity of BHNs, and demonstrate their competitive performance across several tasks (Section 4).

Related Work

We begin with an overview of prior work on Bayesian neural networks in Section 2.1 before discussing the specific components of our technique in Sections 2.2 and 2.3.

Bayesian DNNs have been studied since the 1990s (Neal, 1996; MacKay, 1994). For a thorough review, see Gal (2016). Broadly speaking, existing methods either 1) use Markov chain Monte Carlo (Welling & Teh, 2011; Neal, 1996), or 2) directly learn an approximate posterior distribution using (stochastic) variational inference (Graves, 2011; Gal & Ghahramani, 2016; Salimans et al., 2015; Blundell et al., 2015), expectation propagation (Hernandez-Lobato & Adams, 2015; Soudry et al., 2014), or α\alpha-divergences (Li & Gal, 2017). We focus here on the most popular approach: variational inference.

Notable recent work in this area includes Gal & Ghahramani (2016), who interprets the popular dropout (Srivastava et al., 2014) algorithm as a variational inference method (“MC dropout”). This has the advantages of being simple to implement and allowing cheap samples from q(θ)q({\bm{\mathbf{\theta}}}). Kingma et al. (2015) emulates Gaussian dropout, but yields a unimodal approximate posterior, and does not allow arbitrary dependencies between the parameters.

The other important points of reference for our work are Bayes by Backprop (BbB) (Blundell et al., 2015), and multiplicative normalizing flows (Louizos & Welling, 2017). Bayes by Backprop can be viewed as a special instance of a Bayesian hypernet, where the hypernetwork only performs an element-wise scale and shift of the input noise (yielding a factorial Gaussian distribution).

More similar is the work of Louizos & Welling (2017), who propose and dismiss BHNs due to the issues of scaling BHNs to large primary networks, which we address in Section 3.3. The idea is also explored by Shi et al. (2017), who likewise reject it in favor of their implicit approach which estimates the KL-divergence using a classifier. Instead, in their work, they use a hypernet to generate scaling factors, z\mathbf{z} on the means μ{\bm{\mathbf{\mu}}} of a factorial Gaussian distribution. Because z\mathbf{z} follows a complicated distribution, this forms a highly flexible approximate posterior: q(θ)=∫ ⁣q(θ∣z)q(z)dzq({\bm{\mathbf{\theta}}})=\int\!q({\bm{\mathbf{\theta}}}|\mathbf{z})q(\mathbf{z})d\mathbf{z}. However, this approach also requires them to introduce an auxiliary inference network to approximate q(z∣θ)q(\mathbf{z}|{\bm{\mathbf{\theta}}}) in order to estimate the entropy term of the variational lower bound, resulting in lower bound on the variational lower bound.

Finally, the variational autoencoder (VAE) (Jimenez Rezende et al., 2014; Kingma & Welling, 2013) family of generative models is likely the best known application of variational inference in DNNs, but note that the VAE is not a Bayesian DNN in our sense. VAEs approximate the posterior over latent variables, given a datapoint; Bayesian DNNs approximate the posterior over model parameters, given a dataset.

2 Hypernetworks

A hypernetwork (Ha et al., 2017; Brabandere et al., 2016; Bertinetto et al., 2016) is a neural net that outputs parameters of another neural net (the “primary network”).The name “hypernetwork” comes from Ha et al. (2017), who describe the general hypernet framework, but applications of this idea in convolutional networks were previously explored by Brabandere et al. (2016) and Bertinetto et al. (2016). The hypernet and primary net together form a single model which is trained by backpropagation. The number of parameters of a DNN scales quadratically in the number of units per layer, meaning naively parametrizing a large primary net requires an impractically large hypernet. One method of addressing this challenge is Conditional Batch Norm (CBN) (Dumoulin et al., 2016), and the closely related Conditional Instance Normalization (CIN) (Huang & Belongie, 2017; Ulyanov et al., 2016), and Feature-wise Linear Modulation (FiLM) (Perez et al., 2017; Kirkpatrick et al., 2016), which can be viewed as specific forms of a hypernet. In these works, the weights of the primary net are parametrized directly, and the hypernet only outputs scale (γ\gamma) and shift (β\beta) parameters for every neuron; this can be viewed as selecting which features are significant (scaling) or present (shifting). In our work, we employ the related technique of weight normalization (Salimans & Kingma, 2016), which normalizes the input weights for every neuron and introduces a separate parameter gg for their scale.

3 Invertible Generative Models

Our proposed Bayesian hypernetworks employ a differentiable directed generator network (DDGN) (Goodfellow et al., 2016) as a generative model of the primary net parameters. DDGNs use a neural net to transform simple noise (most commonly isotropic Gaussian) into samples from a complex distribution, and are a common component of modern deep generative models such as variational autoencoders (VAEs) (Kingma & Welling, 2013; Jimenez Rezende et al., 2014) and generative adversarial networks (GANs) (Goodfellow et al., 2014a; Goodfellow, 2017).

We take advantage of techniques for invertible DDGNs developed in several recent works on generative modeling (Dinh et al., 2014; 2016) and variational inference of latent variables (Rezende & Mohamed, 2015; Kingma et al., 2016). Training these models uses the change of variables formula, which involves computing the log-determinant of the inverse Jacobian of the generator network. This computation involves a potentially costly matrix determinant, and these works propose innovative architectures which reduce the cost of this operation but can still express complicated deformations, which are referred to as “normalizing flows”.

Methods

We now describe how variational inference is applied to Bayesian deep nets (Section 3.1), and how we compose the methods described in Sections 2.2 and 2.3 to produce Bayesian hypernets (Section 3.2).

The right hand side of (2) is the evidence lower bound, or “ELBO”.

The above derivation applies to any statistical model and any dataset. In our experiments, we focus on modeling conditional likelihoods p(D)=p(Y∣X)p(\mathcal{D})=p(\mathcal{Y}|\mathcal{X}). Using the conditional independence assumption, we further decompose log⁡p(D∣θ):=log⁡p(Y∣X,θ)\log p(\mathcal{D}|{\bm{\mathbf{\theta}}}):=\log p(\mathcal{Y}|\mathcal{X},{\bm{\mathbf{\theta}}}) as ∑i=1nlog⁡p(yi∣xi,θ)\sum_{i=1}^{n}\log p({\bm{\mathbf{y}}}_{i}|{\bm{\mathbf{x}}}_{i},{\bm{\mathbf{\theta}}}), and apply stochastic gradient methods for optimization.

2 Bayesian Hypernets

To avoid this issue, we use an invertible hh, allowing us to compute q(θ)q({\bm{\mathbf{\theta}}}) simply by using the change of variables formula:

where qϵq_{\bm{\mathbf{\epsilon}}} is the distribution of ϵ{\bm{\mathbf{\epsilon}}} and θ=h(ϵ){\bm{\mathbf{\theta}}}=h(\epsilon).

As discussed in Section 2.3, a number of techniques have been developed for efficiently training such invertible DDGNs. In this work, we employ both RealNVP (RNVP) (Dinh et al., 2016) and Inverse Autoregressive Flows (IAF) (Kingma et al., 2016). Note that the latter can be efficiently applied, since we only require the ability to evaluate likelihood of generated samples (not arbitrary points in the range of hh, as in generative modeling applications, e.g., Dinh et al. (2016)); and this also means that we can use a lower-dimensional ϵ{\bm{\mathbf{\epsilon}}} to generate samples along a submanifold of the entire parameter space, as detailed below.

3 Efficient Parametrization and Training of Bayesian Hypernets

In order to scale BHNs to large primary networks, we use the weight normalization reparametrization (Salimans & Kingma, 2016) Mathematical details can be found in the Appendix, Section B. :

where θj{\bm{\mathbf{\theta}}}_{j} are the input weights associated with a single unit jj in the primary network. We only output the scaling factors gg from the hypernet, and learn a maximum likelihood estimate of v{\bm{\mathbf{v}}}.This parametrization strongly resembles the “correlated” version of variational Gaussian dropout (Kingma et al., 2015, Sec. 3.2); the only difference is that we restrict the u{\bm{\mathbf{u}}} to have norm 1. This allows us to overcome the computational limitations of naively-parametrized BHNs noted by Louizos & Welling (2017), since computation now scales linearly, instead of quadratically, in the number of primary net units. Using this parametrization restricts the family of approximate posteriors, but still allows for a high degree of multimodality and dependence between the parameters.

We also employ weight normalization within the hypernet, and found this stabilizes training dramatically. Initialization plays an important role as well; we recommend initializing the hypernet weights to small values to limit the impact of noise at the beginning of training. We also find clipping the outputs of the softmax to be within (0.001,0.999)(0.001,0.999) critical for numerical stability.

Experiments

We perform experiments on MNIST, CIFAR10, and a 1D regression task. There is no single metric for how well a model captures uncertainty; to evaluate our model, we perform experiments on regularization (Section 4.2), active learning (Section 4.3), anomaly detection (Section 4.4), and detection of adversarial examples (Section 4.5). Active learning and anomaly detection problems make natural use of uncertainty estimates: In anomaly detection, higher uncertainty indicates a likely anomaly. In active learning, higher uncertainty indicates a greater opportunity for learning. Parameter uncertainty also has regularization benefits: integrating over the posterior creates an implicit ensemble. Intuitively, when the most likely hypothesis predicts “A”, but the posterior places more total mass on hypotheses predicting “B”, we prefer predicting “B”. By improving our estimate of the posterior, we more accurately weigh the evidence for different hypotheses. Adversarial examples are an especially difficult kind of anomaly designed to fool a classifier, and finding effective defenses against adversarial attacks remains an open challenge in deep learning.

For the hypernet architecture, we try both RealNVP (Dinh et al., 2016) and IAF(Kingma et al., 2016) with MADE(Germain et al., 2015), with 1-layer ReLU-MLP coupling functions with 200 hidden units (each). In general, we find that IAF performs better. We use an isotropic standard normal prior on the scaling factors (gg) of the weights of the network. We also use Adam with default hyper-parameter settings (Kingma & Ba, 2014) and gradient clipping in all of our experiments. Our mini-batch size is 128, and to reduce computation, we use the same noise-sample (and thus the same primary net parameters) for all examples in a mini-batch. We experimented with independent noise, but did not notice any benefit. Our baselines for comparison are Bayes by Backprop (BbB) (Blundell et al., 2015), MC dropout (MCdropout) (Gal & Ghahramani, 2016), and non-Bayesian DNN baselines (with and without dropout).

We first demonstrate the behavior of the network on the toy 1D-regression problem from Blundell et al. (2015) in Figure 1. As expected, the uncertainty of the network increases away from the observed data. We also use this experiment to evaluate the effects of our proposal for scaling BHNs via the weight norm parametrization (Section 3.3) by comparing with a model which generates the full set of parameters, and find that the two models produce very similar results, suggesting that our proposed method strikes a good balance between scalability and expressiveness.

Next, we demonstrate the distinctive ability of Bayesian hypernets to learn multi-modal, dependent distributions. Figure 6 (appendix) shows that BHNs do learn approximate posteriors with dependence between different parameters, as measured by the Pearson correlation coefficient. Meanwhile, Figure 2 shows that BHNs are capable of learning multimodal posteriors. For this experiment, we trained an over-parametrized linear (primary) network: y^=a⋅b⋅x\hat{y}=a\cdot b\cdot x on a dataset generated as y=x+ϵy=x+\epsilon, and the BHN learns capture both the modes of a=b=1a=b=1 and a=b=−1a=b=-1.

2 Classification

We now show that BHNs act as a regularizer, outperforming dropout and traditional mean field (BbB). Results are presented in Table 1. In our experiments, we find that BHNs perform on par with dropout on full datasets of MNIST and CIFAR10; furthermore, increasing the flexibility of the posterior by adding more coupling layers improves performance, especially compared with models with 0 coupling layers, which cannot model dependencies between the parameters. We also evaluate on a subset of MNIST (the first 5,000 examples); results are presented in the last two columns of Table 1. Replicating these experiments (with 8 coupling layers) for 10 trials yields Figure 3.

In these MNIST experiments, we use MLPs with 2 hidden layers of 800 or 1200 hidden units each. For CIFAR10, we train a convolutional neural net (CNN) with 4 hidden layers of $channels,channels,2\times 2maxpoolingafterthesecondandthefourthlayers,filtersizeofmax pooling after the second and the fourth layers, filter size of3,andasinglefullyconnectedlayerof, and a single fully connected layer of512$ units.

3 Active Learning

We now turn to active learning, where we compare to the MNIST experiments of Gal et al. (2017), replicating their architecture and training procedure. Briefly, they use an initial dataset of 20 examples (2 from each class), and acquire 10 new examples at a time, training for 50 epochs between each acquisition. While Gal et al. (2017) re-initialize the network after every acquisition, we found that “warm-starting” from the current learned parameters was essential for good performance with BHNs, although it is likely that longer training or better initialization schemes could perform the same role. Overall, warm-started BHNs suffered at the beginning of training, but outperformed all other methods for moderate to large numbers of acquisitions.

4 Anomaly Detection

For anomaly detection, we take Hendrycks & Gimpel (2016) as a starting point, and perform the same suite of MNIST experiments, evaluating the ability of networks to determine whether an input came from their training distribution (“Out of distribution detection”). Hendrycks & Gimpel (2016) found that the confidence expressed in the softmax probabilities of a (non-Bayesian) DNN trained on a single dataset provides a good signal for both of these detection problems. We demonstrate that Bayesian DNNs outperform their non-Bayesian counterparts.

Just as in active learning, in anomaly detection, we use MC to estimate the predictive posterior, and use this to score datapoints. For active learning, we would generally like to acquire points where there is higher uncertainty. In a well-calibrated model, these points are also likely to be challenging or anomalous examples, and thus acquisition functions from the active learning literature are good candidates for scoring anomalies.

We consider all of the acquisition functions listed in (Gal et al., 2017) as possible scores for the Area Under the Curve (AUC) of Precision-Recall (PR) and Receiver Operating Characteristic (ROC) metrics, but found that the maximum confidence of the softmax probabilities (i.e., “variation ratio”) acquisition function used by Hendrycks & Gimpel (2016) gave the best performance. Both BHN and MCdropout achieve significant performance gains over the non-Bayesian baseline, and MCdropout performs significantly better than BHN in this task. Results are presented in Table 2.

Second, we follow the same experimental setup, using all the acquisition functions, and exclude one class in the training set of MNIST at a time. We take the excluded class of the training data as out-of-distribution samples. The result is presented in Table 3 (Appendix). This experiment shows the benefit of using scores that reflect dispersion in the posterior samples (such as mean standard deviation and BALD value) in Bayesian DNNs.

5 Adversary Detection

Finally, we consider this same anomaly detection procedure as a novel tool for detecting adversarial examples. Our setup is similar to Li & Gal (2017) and Louizos & Welling (2017), where it is shown that when more perturbation is added to the data, model uncertainty increases and then drops. We use the Fast Gradient Sign method (FGS) (Goodfellow et al., 2014b) for adversarial attack, and use one sample of our model to estimate the gradient. Li & Gal (2017) and Louizos & Welling (2017) used 10 and 1 model samples, respectively, to estimate gradient. We report the result with 1 sample; results with more samples are given in the appendix. We find that, compared with dropout, BHNs are less confident on data points which are far from the data manifold. In particular, BHNs constructed with IAF consistently outperform RealNVP-BHNs and dropout in detecting adversarial examples and errors. Results are shown in Figure 5.

Conclusions

We introduce Bayesian hypernets (BHNs), a new method for variational Bayesian deep learning which uses an invertible hypernetwork as a generative model of parameters. BHNs feature efficient training and sampling, and can express complicated multimodal distributions, thereby addressing issues of overconfidence present in simpler variational approximations. We present a method of parametrizing BHNs which allows them to scale successfully to real world tasks, and show that BHNs can offer significant benefits over simpler methods for Bayesian deep learning. Future work could explore other methods of parametrizing BHNs, for instance using the same hypernet to output different subsets of the primary net parameters.

References

Appendix A Additional Results

A.2 Unseen mode detection

We replicate the experiments of anomaly detection with unseen classes of MNIST.

A.3 Stronger attack

Here we use 32 samples to estimate the gradient direction with respect to the input. A better estimate of gradient amounts to a stronger attack, so accuracy drops lower for a given step size while an adversarial example can be more easily detected with a more informative uncertainty measure.

Appendix B Derivation of training objective

In this paper, we employ weight normalization in the primary network (7), treating (only) the scaling factors g{\bm{\mathbf{g}}} as random variables. We choose an isotropic Gaussian prior for g{\bm{\mathbf{g}}}: p(g)=N(g;0,λI)p({\bm{\mathbf{g}}})=\mathcal{N}({\bm{\mathbf{g}}};{\bm{\mathbf{0}}},\lambda\mathbf{I}), which results in an L2L_{2} weight-decay penalty on g{\bm{\mathbf{g}}}, or, equivalently, w=gv∣∣v∣∣2{\bm{\mathbf{w}}}={\bm{\mathbf{g}}}\frac{{\bm{\mathbf{v}}}}{||{\bm{\mathbf{v}}}||_{2}}. Our objective and lower bound are then:

where v{\bm{\mathbf{v}}} and b{\bm{\mathbf{b}}} are the direction and bias parameters of the primary net, and ϕ\phi is the parameters of the hypernetwork. We optimize this bound with respect to {v,b,ϕ}\{{\bm{\mathbf{v}}},{\bm{\mathbf{b}}},\phi\} during training.