Certifying Geometric Robustness of Neural Networks

被引:0
|
作者
Balunovic, Mislav [1 ]
Baader, Maximilian [1 ]
Singh, Gagandeep [1 ]
Gehr, Timon [1 ]
Vechev, Martin [1 ]
机构
[1] Swiss Fed Inst Technol, Dept Comp Sci, Zurich, Switzerland
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The use of neural networks in safety-critical computer vision systems calls for their robustness certification against natural geometric transformations (e.g., rotation, scaling). However, current certification methods target mostly norm-based pixel perturbations and cannot certify robustness against geometric transformations. In this work, we propose a new method to compute sound and asymptotically optimal linear relaxations for any composition of transformations. Our method is based on a novel combination of sampling and optimization. We implemented the method in a system called DEEPG and demonstrated that it certifies significantly more complex geometric transformations than existing methods on both defended and undefended networks while scaling to large architectures.
引用
收藏
页数:11
相关论文
共 50 条
  • [21] Probabilistic Robustness Quantification of Neural Networks
    Kishan, Gopi
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 15966 - 15967
  • [22] Design quality and robustness with neural networks
    Ali, ÖG
    Chen, YT
    IEEE TRANSACTIONS ON NEURAL NETWORKS, 1999, 10 (06): : 1518 - 1527
  • [23] ON THE HYSTERESIS AND ROBUSTNESS OF HOPFIELD NEURAL NETWORKS
    SCHONFELD, D
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS II-ANALOG AND DIGITAL SIGNAL PROCESSING, 1993, 40 (11): : 745 - 748
  • [24] Noise robustness in multilayer neural networks
    Copelli, M.
    Eichhorn, R.
    Kinouchi, O.
    Biehl, M.
    Europhysics Letters, 37 (06):
  • [25] Stochasticity and robustness in spiking neural networks
    Olin-Ammentorp, Wilkie
    Beckmann, Karsten
    Schuman, Catherine D.
    Plank, James S.
    Cady, Nathaniel C.
    NEUROCOMPUTING, 2021, 419 : 23 - 36
  • [26] Noise robustness in multilayer neural networks
    Copelli, M
    Eichhorn, R
    Kinouchi, O
    Biehl, M
    Simonetti, R
    Riegler, P
    Caticha, N
    EUROPHYSICS LETTERS, 1997, 37 (06): : 427 - 432
  • [27] On Robustness and Transferability of Convolutional Neural Networks
    Djolonga, Josip
    Yung, Jessica
    Tschannen, Michael
    Romijnders, Rob
    Beyer, Lucas
    Kolesnikov, Alexander
    Puigcerver, Joan
    Minderer, Matthias
    D'Amour, Alexander
    Moldovan, Dan
    Gelly, Sylvain
    Houlsby, Neil
    Zhai, Xiaohua
    Lucic, Mario
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 16453 - 16463
  • [28] Towards Evaluating the Robustness of Neural Networks
    Carlini, Nicholas
    Wagner, David
    2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, : 39 - 57
  • [29] Quantitative Robustness Analysis of Neural Networks
    Downing, Mara
    PROCEEDINGS OF THE 32ND ACM SIGSOFT INTERNATIONAL SYMPOSIUM ON SOFTWARE TESTING AND ANALYSIS, ISSTA 2023, 2023, : 1527 - 1531
  • [30] Wasserstein distributional robustness of neural networks
    Bai, Xingjian
    Jiang, Yifan
    He, Guangyi
    Oblój, Jan
    Advances in Neural Information Processing Systems, 2023, 36