DeepCert: Verification of Contextually Relevant Robustness for Neural Network Image Classifiers

DeepCert: Verification of Contextually Relevant Robustness for Neural Network Image Classifiers
复制标题

DOI:
10.1007/978-3-030-83903-1_5
复制
发表时间:
2021-03
期刊:
--
影响因子:
--
通讯作者:
Colin Paterson;Haoze Wu;John M. Grese;R. Calinescu;C. Păsăreanu;Clark W. Barrett
Colin Paterson;Haoze Wu;John M. Grese;R. Calinescu;C. Păsăreanu;Clark W. Barrett
中科院分区:
其他
文献类型:
--
作者:
Colin Paterson;Haoze Wu;John M. Grese;R. Calinescu;C. Păsăreanu;Clark W. Barrett

文献摘要

被引文献

相似文献

我们介绍了DeepCert,这是一种工具支持的方法,用于验证深度神经网络(DNN)图像分类器对上下文相关扰动(如模糊,雾度和图像对比度变化)的鲁棒性。虽然DNN分类器的鲁棒性近年来一直是激烈研究的主题,但本研究提供的解决方案侧重于验证DNN对分类图像中小扰动的鲁棒性,并使用已建立的范数测量扰动幅度。这对于识别对DNN图像分类器的潜在对抗性攻击很有用,但无法验证DNN对上下文相关图像扰动的鲁棒性,这些扰动在用范数表示时通常不小。DeepCert通过支持以下内容解决了这个未充分探索的验证问题:(1)真实世界图像扰动的编码;(2)使用测试和形式验证对上下文相关的DNN鲁棒性进行系统评估;(3)生成上下文相关的反例;以及,通过这些,(4)选择适合于操作环境的DNN图像分类器(i)当设计潜在安全关键系统时所设想的,或(ii)由部署的系统观察到。我们通过展示如何使用DeepCert来验证DNN图像分类器对两个基准数据集(“德国交通标志”和“CIFAR-10”)的鲁棒性来证明DeepCert的有效性。
We introduce DeepCert, a tool-supported method for verifying the robustness of deep neural network (DNN) image classifiers tocontextually relevant perturbationssuch as blur, haze, and changes in image contrast. While the robustness of DNN classifiers has been the subject of intense research in recent years, the solutions delivered by this research focus on verifying DNN robustness to small perturbations in the images being classified, with perturbation magnitude measured using establishednorms. This is useful for identifying potential adversarial attacks on DNN image classifiers, but cannot verify DNN robustness to contextually relevant image perturbations, which are typically not small when expressed withnorms. DeepCert addresses this underexplored verification problem by supporting: (1) the encoding of real-world image perturbations; (2) the systematic evaluation of contextually relevant DNN robustness, using both testing and formal verification; (3) the generation of contextually relevant counterexamples; and, through these, (4) the selection of DNN image classifiers suitable for the operational context (i) envisaged when a potentially safety-critical system is designed, or (ii) observed by a deployed system. We demonstrate the effectiveness of DeepCert by showing how it can be used to verify the robustness of DNN image classifiers build for two benchmark datasets (‘German Traffic Sign’ and ‘CIFAR-10’) to multiple contextually relevant perturbations.