Boosting robustness verification of semantic feature neighborhoods
From MaRDI portal
Publication:6164433
DOI10.1007/978-3-031-22308-2_14zbMATH Open1524.68319arXiv2209.05446MaRDI QIDQ6164433FDOQ6164433
Authors: Anan Kabaha, Dana Drachsler-Cohen
Publication date: 28 July 2023
Published in: Static Analysis (Search for Journal in Brave)
Abstract: Deep neural networks have been shown to be vulnerable to adversarial attacks that perturb inputs based on semantic features. Existing robustness analyzers can reason about semantic feature neighborhoods to increase the networks' reliability. However, despite the significant progress in these techniques, they still struggle to scale to deep networks and large neighborhoods. In this work, we introduce VeeP, an active learning approach that splits the verification process into a series of smaller verification steps, each is submitted to an existing robustness analyzer. The key idea is to build on prior steps to predict the next optimal step. The optimal step is predicted by estimating the certification velocity and sensitivity via parametric regression. We evaluate VeeP on MNIST, Fashion-MNIST, CIFAR-10 and ImageNet and show that it can analyze neighborhoods of various features: brightness, contrast, hue, saturation, and lightness. We show that, on average, given a 90 minute timeout, VeeP verifies 96% of the maximally certifiable neighborhoods within 29 minutes, while existing splitting approaches verify, on average, 73% of the maximally certifiable neighborhoods within 58 minutes.
Full work available at URL: https://arxiv.org/abs/2209.05446
Recommendations
- Robustness verification of semantic segmentation neural networks using relaxed reachability
- DeepSafe: a data-driven approach for assessing robustness of neural networks
- Improving neural network verification through spurious region guided refinement
- Enhancing robustness verification for deep neural networks via symbolic propagation
- Verification of deep convolutional neural networks using ImageStars
Artificial neural networks and deep learning (68T07) Specification and verification (program logics, model checking, etc.) (68Q60)
Cites Work
- Learning regular sets from queries and counterexamples
- Title not available (Why is that?)
- Reluplex: an efficient SMT solver for verifying deep neural networks
- Verification of deep convolutional neural networks using ImageStars
- An abstraction-based framework for neural network verification
- Branch and bound for piecewise linear neural network verification
- Scalable polyhedral verification of recurrent neural networks
- Principal Component Adversarial Example
Cited In (1)
This page was built for publication: Boosting robustness verification of semantic feature neighborhoods
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q6164433)