Provably Tightest Linear Approximation for Robustness Verification of Sigmoid-like Neural Networks

被引:1
|
作者
Zhang, Zhaodi [1 ]
Wu, Yiting [1 ]
Liu, Si [2 ]
Liu, Jing [3 ]
Zhang, Min [1 ,4 ]
机构
[1] East China Normal Univ, Shanghai, Peoples R China
[2] Swiss Fed Inst Technol, Zurich, Switzerland
[3] East China Normal Univ, Shanghai Key Lab Trustworthy Comp, Shanghai, Peoples R China
[4] East China Normal Univ, Shanghai Inst Intelligent Sci & Technol, Shanghai, Peoples R China
关键词
REFINEMENT;
D O I
10.1145/3551349.3556907
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The robustness of deep neural networks is crucial to modern AIenabled systems and should be formally verified. Sigmoid-like neural networks have been adopted in a wide range of applications. Due to their non-linearity, Sigmoid-like activation functions are usually over-approximated for efficient verification, which inevitably introduces imprecision. Considerable efforts have been devoted to finding the so-called tighter approximations to obtain more precise verification results. However, existing tightness definitions are heuristic and lack theoretical foundations. We conduct a thorough empirical analysis of existing neuron-wise characterizations of tightness and reveal that they are superior only on specific neural networks. We then introduce the notion of network-wise tightness as a unified tightness definition and show that computing networkwise tightness is a complex non-convex optimization problem. We bypass the complexity from different perspectives via two efficient, provably tightest approximations. The results demonstrate the promising performance achievement of our approaches over state of the art: (i) achieving up to 251.28% improvement to certified lower robustness bounds; and (ii) exhibiting notably more precise verification results on convolutional networks.
引用
收藏
页数:13
相关论文
共 50 条
  • [41] Universal Approximation of Nonlinear System Predictions in Sigmoid Activation Functions Using Artificial Neural Networks
    Murugadoss, R.
    Ramakrishnan, M.
    2014 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND COMPUTING RESEARCH (IEEE ICCIC), 2014, : 1062 - 1067
  • [42] STABILITY, ROBUSTNESS AND APPROXIMATION PROPERTIES OF GRADIENT RECURRENT HIGH-ORDER NEURAL NETWORKS
    KOSMATOPOULOS, EB
    CHRISTODOULOU, MA
    INTERNATIONAL JOURNAL OF ADAPTIVE CONTROL AND SIGNAL PROCESSING, 1994, 8 (04) : 393 - 406
  • [43] Verification of LSTM Neural Networks with Non-linear Activation Functions
    Moradkhani, Farzaneh
    Fibich, Connor
    Franzle, Martin
    NASA FORMAL METHODS, NFM 2023, 2023, 13903 : 1 - 15
  • [44] Neural networks: A general framework for non-linear function approximation
    Institute for Economic Geography and GIScience, Vienna University of Economics and Business Administration, Nordbergstr. 15, Vienna A-1090, Austria
    1600, 521-533 (July 2006):
  • [45] Linear Approximation of Deep Neural Networks for Efficient Inference on Video Data
    Rueckauer, Bodo
    Liu, Shih-Chii
    2019 27TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO), 2019,
  • [46] Robustness Verification of Deep Neural Networks on High-speed Rail Operating Environment Recognition
    Gao Z.
    Su Y.
    Hou X.
    Fang P.
    Zhang M.
    Tongji Daxue Xuebao/Journal of Tongji University, 2022, 50 (10): : 1405 - 1413
  • [47] NeuroDiff: Scalable Differential Verification of Neural Networks using Fine-Grained Approximation
    Paulsen, Brandon
    Wang, Jingbo
    Wang, Jiawei
    Wang, Chao
    2020 35TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE 2020), 2020, : 784 - 796
  • [48] Approximation and Optimization Theory for Linear Continuous-Time Recurrent Neural Networks
    Li, Zhong
    Han, Jiequn
    E, Weinan
    Li, Qianxiao
    JOURNAL OF MACHINE LEARNING RESEARCH, 2022, 23 : 1 - 85
  • [49] Approximation and Optimization Theory for Linear Continuous-Time Recurrent Neural Networks
    Li, Zhong
    Han, Jiequn
    Weinan, E.
    Li, Qianxiao
    Journal of Machine Learning Research, 2022, 23
  • [50] LIGHT FIELD IMAGE COMPRESSION BASED ON CONVOLUTIONAL NEURAL NETWORKS AND LINEAR APPROXIMATION
    Bakir, Nader
    Hamidouche, Wassim
    Deforges, Olivier
    Samrouth, Khouloud
    Khalil, Mohamad
    2018 25TH IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2018, : 1128 - 1132