Towards Verifying the Geometric Robustness of Large-Scale Neural Networks

被引:0
|
作者
Wang, Fu [1 ]
Xu, Peipei [2 ]
Ruan, Wenjie [1 ]
Huang, Xiaowei [2 ]
机构
[1] Univ Exeter, Dept Comp Sci, Exeter EX4 4QF, Devon, England
[2] Univ Liverpool, Dept Comp Sci, Liverpool L69 3BX, Merseyside, England
基金
英国工程与自然科学研究理事会;
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep neural networks (DNNs) are known to be vulnerable to adversarial geometric transformation. This paper aims to verify the robustness of large-scale DNNs against the combination of multiple geometric transformations with a provable guarantee. Given a set of transformations (e.g., rotation, scaling, etc.), we develop GeoRobust, a black-box robustness analyser built upon a novel global optimisation strategy, for locating the worst-case combination of transformations that affect and even alter a network's output. GeoRobust can provide provable guarantees on finding the worstcase combination based on recent advances in Lipschitzian theory. Due to its black-box nature, GeoRobust can be deployed on large-scale DNNs regardless of their architectures, activation functions, and the number of neurons. In practice, GeoRobust can locate the worst-case geometric transformation with high precision for the ResNet50 model on ImageNet in a few seconds on average. We examined 18 ImageNet classifiers, including the ResNet family and vision transformers, and found a positive correlation between the geometric robustness of the networks and the parameter numbers. We also observe that increasing the depth of DNN is more beneficial than increasing its width in terms of improving its geometric robustness. Our tool GeoRobust is available at https://github.com/TrustAI/GeoRobust.
引用
收藏
页码:15197 / 15205
页数:9
相关论文
共 50 条
  • [31] On the Utility of Concave Nodes in Geometric Processing of Large-Scale Sensor Networks
    Zhang, Shengkai
    Tan, Guang
    Jiang, Hongbo
    Li, Bo
    Wang, Chonggang
    [J]. IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2014, 13 (01) : 132 - 143
  • [32] Bounding the Complexity of Formally Verifying Neural Networks: A Geometric Approach
    Ferlez, James
    Shoukry, Yasser
    [J]. 2021 60TH IEEE CONFERENCE ON DECISION AND CONTROL (CDC), 2021, : 5104 - 5109
  • [33] Improved Geometric Path Enumeration for Verifying ReLU Neural Networks
    Bak, Stanley
    Hoang-Dung Tran
    Hobbs, Kerianne
    Johnson, Taylor T.
    [J]. COMPUTER AIDED VERIFICATION (CAV 2020), PT I, 2020, 12224 : 66 - 96
  • [34] Towards fast hemodynamic simulations in large-scale circulatory networks
    Alvarez, L. A. Mansilla
    Blancoa, P. J.
    Bulant, C. A.
    Feijoo, R. A.
    [J]. COMPUTER METHODS IN APPLIED MECHANICS AND ENGINEERING, 2019, 344 : 734 - 765
  • [35] Towards Online Multiresolution Community Detection in Large-Scale Networks
    Huang, Jianbin
    Sun, Heli
    Liu, Yaguang
    Song, Qinbao
    Weninger, Tim
    [J]. PLOS ONE, 2011, 6 (08):
  • [36] Researches of the Topology Robustness of Large-scale Complex Networks under Hybrid Attacks
    Xu, Ye
    Zhao, Xingyu
    [J]. 2017 2ND AASRI INTERNATIONAL CONFERENCE ON INDUSTRIAL ELECTRONICS AND APPLICATIONS (IEA 2017), 2017, : 13 - 18
  • [37] A robustness distributed system with sensing and fault detection for large-scale sensor networks
    Hattori, Kiyohiko
    Takadama, Keiki
    Murata, Satoshi
    Furuya, Hiroshi
    [J]. PROCEEDINGS OF SICE ANNUAL CONFERENCE, VOLS 1-8, 2007, : 1157 - 1161
  • [38] Verifying Attention Robustness of Deep Neural Networks Against Semantic Perturbations
    Munakata, Satoshi
    Urban, Caterina
    Yokoyama, Haruki
    Yamamoto, Koji
    Munakata, Kazuki
    [J]. NASA FORMAL METHODS, NFM 2023, 2023, 13903 : 37 - 61
  • [39] Verifying Attention Robustness of Deep Neural Networks against Semantic Perturbations
    Munakata, Satoshi
    Urban, Caterina
    Yokoyama, Haruki
    Yamamoto, Koji
    Munakata, Kazuki
    [J]. 2022 29TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE, APSEC, 2022, : 560 - 561
  • [40] Modeling and analysis of large-scale computer networks' robustness based on the scale-free theory
    Yao Yi
    Liu Xiaoming
    Huang Song
    [J]. Advanced Computer Technology, New Education, Proceedings, 2007, : 788 - 791