Verification of Neural Networks' Global Robustness

被引:0
|
作者
Kabaha, Anan [1 ]
Cohen, Dana Drachsler [1 ]
机构
[1] Technion, Haifa, Israel
来源
基金
以色列科学基金会;
关键词
Neural Network Verification; Global Robustness; Constrained Optimization;
D O I
10.1145/3649847
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Neural networks are successful in various applications but are also susceptible to adversarial attacks. To show the safety of network classifiers, many verifiers have been introduced to reason about the local robustness of a given input to a given perturbation. While successful, local robustness cannot generalize to unseen inputs. Several works analyze global robustness properties, however, neither can provide a precise guarantee about the cases where a network classifier does not change its classification. In this work, we propose a new global robustness property for classifiers aiming at finding the minimal globally robust bound, which naturally extends the popular local robustness property for classifiers. We introduce VHAGaR, an anytime verifier for computing this bound. VHAGaR relies on three main ideas: encoding the problem as a mixed-integer programming and pruning the search space by identifying dependencies stemming from the perturbation or the network's computation and generalizing adversarial attacks to unknown inputs. We evaluate VHAGaR on several datasets and classifiers and show that, given a three hour timeout, the average gap between the lower and upper bound on the minimal globally robust bound computed by VHAGaR is 1.9, while the gap of an existing global robustness verifier is 154.7. Moreover, VHAGaR is 130.6x faster than this verifier. Our results further indicate that leveraging dependencies and adversarial attacks makes VHAGaR 78.6x faster.
引用
收藏
页数:30
相关论文
共 50 条
  • [21] Improving Robustness Verification of Neural Networks with General Activation Functions via Branching and Optimization
    Luo, Zhengwu
    Wang, Lina
    Wang, Run
    Yang, Kang
    Ye, Aoshuang
    2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,
  • [22] Safety Verification and Robustness Analysis of Neural Networks via Quadratic Constraints and Semidefinite Programming
    Fazlyab, Mahyar
    Morari, Manfred
    Pappas, George J.
    IEEE TRANSACTIONS ON AUTOMATIC CONTROL, 2022, 67 (01) : 1 - 15
  • [23] Robustness Evaluation and Prioritization Verification for Deep Neural Networks via Decision Boundary Analysis
    Lin R.-H.
    Zhou Q.-L.
    Hu T.-Q.
    Wang Y.-F.
    Jisuanji Xuebao/Chinese Journal of Computers, 2024, 47 (04): : 862 - 876
  • [24] Tightening Robustness Verification of Convolutional Neural Networks with Fine-Grained Linear Approximation
    Wu, Yiting
    Zhang, Min
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 11674 - 11681
  • [25] Neuron Pairs in Binarized Neural Networks Robustness Verification via Integer Linear Programming
    Lubczyk, Dymitr
    Neto, Jose
    COMBINATORIAL OPTIMIZATION, ISCO 2024, 2024, 14594 : 305 - 317
  • [26] Provably Tightest Linear Approximation for Robustness Verification of Sigmoid-like Neural Networks
    Zhang, Zhaodi
    Wu, Yiting
    Liu, Si
    Liu, Jing
    Zhang, Min
    PROCEEDINGS OF THE 37TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE 2022, 2022,
  • [27] OCCROB: Efficient SMT-Based Occlusion Robustness Verification of Deep Neural Networks
    Guo, Xingwu
    Zhou, Ziwei
    Zhang, Yueling
    Katz, Guy
    Zhang, Min
    TOOLS AND ALGORITHMS FOR THE CONSTRUCTION AND ANALYSIS OF SYSTEMS, PT I, TACAS 2023, 2023, 13993 : 208 - 226
  • [28] Robustness in biological neural networks
    Kalampokis, A
    Kotsavasiloglou, C
    Argyrakis, P
    Baloyannis, S
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2003, 317 (3-4) : 581 - 590
  • [29] Global Robustness Evaluation of Deep Neural Networks with Provable Guarantees for the Hamming Distance
    Ruan, Wenjie
    Wu, Min
    Sun, Youcheng
    Huang, Xiaowei
    Kroening, Daniel
    Kwiatkowska, Marta
    PROCEEDINGS OF THE TWENTY-EIGHTH INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2019, : 5944 - 5952
  • [30] On the robustness of global exponential stability for hybrid neural networks with noise and delay perturbations
    Feng Jiang
    Hua Yang
    Yi Shen
    Neural Computing and Applications, 2014, 24 : 1497 - 1504