跳到主要导航 跳到搜索 跳到主要内容

Provably Tightest Linear Approximation for Robustness Verification of Sigmoid-like Neural Networks

  • East China Normal University
  • Swiss Federal Institute of Technology Zurich

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

The robustness of deep neural networks is crucial to modern AI-enabled systems and should be formally verified. Sigmoid-like neural networks have been adopted in a wide range of applications. Due to their non-linearity, Sigmoid-like activation functions are usually over-approximated for efficient verification, which inevitably introduces imprecision. Considerable efforts have been devoted to finding the so-called tighter approximations to obtain more precise verification results. However, existing tightness definitions are heuristic and lack theoretical foundations. We conduct a thorough empirical analysis of existing neuron-wise characterizations of tightness and reveal that they are superior only on specific neural networks. We then introduce the notion of network-wise tightness as a unified tightness definition and show that computing network-wise tightness is a complex non-convex optimization problem. We bypass the complexity from different perspectives via two efficient, provably tightest approximations. The results demonstrate the promising performance achievement of our approaches over state of the art: (i) achieving up to 251.28% improvement to certified lower robustness bounds; and (ii) exhibiting notably more precise verification results on convolutional networks.

源语言英语
主期刊名37th IEEE/ACM International Conference on Automated Software Engineering, ASE 2022
编辑Mario Aehnelt, Thomas Kirste
出版商Association for Computing Machinery
ISBN(电子版)9781450396240
DOI
出版状态已出版 - 19 9月 2022
活动37th IEEE/ACM International Conference on Automated Software Engineering, ASE 2022 - Rochester, 美国
期限: 10 10月 202214 10月 2022

出版系列

姓名ACM International Conference Proceeding Series

会议

会议37th IEEE/ACM International Conference on Automated Software Engineering, ASE 2022
国家/地区美国
Rochester
时期10/10/2214/10/22

指纹

探究 'Provably Tightest Linear Approximation for Robustness Verification of Sigmoid-like Neural Networks' 的科研主题。它们共同构成独一无二的指纹。

引用此