Towards Verifying the Geometric Robustness of Large-Scale Neural Networks

被引:0
|
作者
Wang, Fu [1 ]
Xu, Peipei [2 ]
Ruan, Wenjie [1 ]
Huang, Xiaowei [2 ]
机构
[1] Univ Exeter, Dept Comp Sci, Exeter EX4 4QF, Devon, England
[2] Univ Liverpool, Dept Comp Sci, Liverpool L69 3BX, Merseyside, England
基金
英国工程与自然科学研究理事会;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks (DNNs) are known to be vulnerable to adversarial geometric transformation. This paper aims to verify the robustness of large-scale DNNs against the combination of multiple geometric transformations with a provable guarantee. Given a set of transformations (e.g., rotation, scaling, etc.), we develop GeoRobust, a black-box robustness analyser built upon a novel global optimisation strategy, for locating the worst-case combination of transformations that affect and even alter a network's output. GeoRobust can provide provable guarantees on finding the worstcase combination based on recent advances in Lipschitzian theory. Due to its black-box nature, GeoRobust can be deployed on large-scale DNNs regardless of their architectures, activation functions, and the number of neurons. In practice, GeoRobust can locate the worst-case geometric transformation with high precision for the ResNet50 model on ImageNet in a few seconds on average. We examined 18 ImageNet classifiers, including the ResNet family and vision transformers, and found a positive correlation between the geometric robustness of the networks and the parameter numbers. We also observe that increasing the depth of DNN is more beneficial than increasing its width in terms of improving its geometric robustness. Our tool GeoRobust is available at https://github.com/TrustAI/GeoRobust.
引用
收藏
页码:15197 / 15205
页数:9
相关论文
共 50 条
  • [21] Visualization of density relations in large-scale neural networks
    Nadasdy, Z
    Zaborszky, L
    [J]. ANATOMY AND EMBRYOLOGY, 2001, 204 (04): : 303 - 317
  • [22] Hierarchical Bipartite Graph Neural Networks: Towards Large-Scale E-commerce Applications
    Li, Zhao
    Shen, Xin
    Jiao, Yuhang
    Pan, Xuming
    Zou, Pengcheng
    Meng, Xianling
    Yao, Chengwei
    Bu, Jiajun
    [J]. 2020 IEEE 36TH INTERNATIONAL CONFERENCE ON DATA ENGINEERING (ICDE 2020), 2020, : 1677 - 1688
  • [23] Video Coding for Machines: Large-Scale Evaluation of Deep Neural Networks Robustness to Compression Artifacts for Semantic Segmentation
    Marie, Alban
    Desnos, Karol
    Morin, Luce
    Zhang, Lu
    [J]. 2022 IEEE 24TH INTERNATIONAL WORKSHOP ON MULTIMEDIA SIGNAL PROCESSING (MMSP), 2022,
  • [24] Towards Evaluating the Robustness of Neural Networks
    Carlini, Nicholas
    Wagner, David
    [J]. 2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, : 39 - 57
  • [25] Neural-Event-Triggered fMRI of large-scale neural networks
    Logothetis, Nikos K.
    [J]. CURRENT OPINION IN NEUROBIOLOGY, 2015, 31 : 214 - 222
  • [26] Towards the robustness of dynamic loop scheduling on large-scale heterogeneous distributed systems
    Banicescu, Ioana
    Ciorba, Florina M.
    Carino, Ricolindo L.
    [J]. EIGHTH INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED COMPUTING, PROCEEDINGS, 2009, : 129 - +
  • [27] Population networks: A large-scale framework for modelling cortical neural networks
    Mallot, HA
    Giannakopoulos, F
    [J]. BIOLOGICAL CYBERNETICS, 1996, 75 (06) : 441 - 452
  • [28] Towards Large-Scale Photonic Neural-Network Accelerators
    Hamerly, R.
    Sludds, A.
    Bernstein, L.
    Prabhu, M.
    Roques-Carmes, C.
    Carolan, J.
    Yamamoto, Y.
    Soljacic, M.
    Englund, D.
    [J]. 2019 IEEE INTERNATIONAL ELECTRON DEVICES MEETING (IEDM), 2019,
  • [29] On the Utility of Concave Nodes in Geometric Processing of Large-Scale Sensor Networks
    Zhang, Shengkai
    Tan, Guang
    Jiang, Hongbo
    Li, Bo
    Wang, Chonggang
    [J]. IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2014, 13 (01) : 132 - 143
  • [30] Robustness of Graph Neural Networks at Scale
    Geisler, Simon
    Schmidt, Tobias
    Sirin, Hakan
    Zuegner, Daniel
    Bojchevski, Aleksandar
    Guennemann, Stephan
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021), 2021, 34