Verification of Neural Networks' Global Robustness

被引:0
|
作者
Kabaha, Anan [1 ]
Cohen, Dana Drachsler [1 ]
机构
[1] Technion, Haifa, Israel
来源
基金
以色列科学基金会;
关键词
Neural Network Verification; Global Robustness; Constrained Optimization;
D O I
10.1145/3649847
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Neural networks are successful in various applications but are also susceptible to adversarial attacks. To show the safety of network classifiers, many verifiers have been introduced to reason about the local robustness of a given input to a given perturbation. While successful, local robustness cannot generalize to unseen inputs. Several works analyze global robustness properties, however, neither can provide a precise guarantee about the cases where a network classifier does not change its classification. In this work, we propose a new global robustness property for classifiers aiming at finding the minimal globally robust bound, which naturally extends the popular local robustness property for classifiers. We introduce VHAGaR, an anytime verifier for computing this bound. VHAGaR relies on three main ideas: encoding the problem as a mixed-integer programming and pruning the search space by identifying dependencies stemming from the perturbation or the network's computation and generalizing adversarial attacks to unknown inputs. We evaluate VHAGaR on several datasets and classifiers and show that, given a three hour timeout, the average gap between the lower and upper bound on the minimal globally robust bound computed by VHAGaR is 1.9, while the gap of an existing global robustness verifier is 154.7. Moreover, VHAGaR is 130.6x faster than this verifier. Our results further indicate that leveraging dependencies and adversarial attacks makes VHAGaR 78.6x faster.
引用
收藏
页数:30
相关论文
共 50 条
  • [1] DeepGlobal: A framework for global robustness verification of feedforward neural networks
    Sun, Weidi
    Lu, Yuteng
    Zhang, Xiyue
    Sun, Meng
    [J]. JOURNAL OF SYSTEMS ARCHITECTURE, 2022, 128
  • [2] Robustness Verification in Neural Networks
    Wurm, Adrian
    [J]. INTEGRATION OF CONSTRAINT PROGRAMMING, ARTIFICIAL INTELLIGENCE, AND OPERATIONS RESEARCH, PT II, CPAIOR 2024, 2024, 14743 : 263 - 278
  • [3] Survey on Robustness Verification of Feedforward Neural Networks and Recurrent Neural Networks
    Liu, Ying
    Yang, Peng-Fei
    Zhang, Li-Jun
    Wu, Zhi-Lin
    Feng, Yuan
    [J]. Ruan Jian Xue Bao/Journal of Software, 2023, 34 (07): : 1 - 33
  • [4] Robustness Verification Boosting for Deep Neural Networks
    Feng, Chendong
    [J]. 2019 6TH INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND CONTROL ENGINEERING (ICISCE 2019), 2019, : 531 - 535
  • [5] PRODEEP: A Platform for Robustness Verification of Deep Neural Networks
    Li, Renjue
    Li, Jianlin
    Huang, Cheng-Chao
    Yang, Pengfei
    Huang, Xiaowei
    Zhang, Lijun
    Xue, Bai
    Hermanns, Holger
    [J]. PROCEEDINGS OF THE 28TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING (ESEC/FSE '20), 2020, : 1630 - 1634
  • [6] Theoretical analysis of norm selection for robustness verification of neural networks
    Saengsawang, Saharat
    Li, Guoqiang
    [J]. PHYSICAL COMMUNICATION, 2023, 58
  • [7] A Convex Relaxation Barrier to Tight Robustness Verification of Neural Networks
    Salman, Hadi
    Yang, Greg
    Zhang, Huan
    Hsieh, Cho-Jui
    Zhang, Pengchuan
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 32 (NIPS 2019), 2019, 32
  • [8] Eager Falsification for Accelerating Robustness Verification of Deep Neural Networks
    Guo, Xingwu
    Wan, Wenjie
    Zhang, Zhaodi
    Zhang, Min
    Song, Fu
    Wen, Xuejun
    [J]. 2021 IEEE 32ND INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE 2021), 2021, : 345 - 356
  • [9] A Parallel Optimization Method for Robustness Verification of Deep Neural Networks
    Lin, Renhao
    Zhou, Qinglei
    Nan, Xiaofei
    Hu, Tianqing
    [J]. MATHEMATICS, 2024, 12 (12)
  • [10] Attack-Guided Efficient Robustness Verification of ReLU Neural Networks
    Zhu, Yiwei
    Wang, Feng
    Wan, Wenjie
    Zhang, Min
    [J]. 2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,