A Sequential Framework Towards an Exact SDP Verification of Neural Networks

A Sequential Framework Towards an Exact SDP Verification of Neural Networks
复制标题

DOI:
10.1109/dsaa53316.2021.9564161
复制
发表时间:
2020-10
期刊:
2021 IEEE 8th International Conference on Data Science and Advanced Analytics (DSAA)
影响因子:
--
通讯作者:
Ziye Ma;S. Sojoudi
Ziye Ma;S. Sojoudi
中科院分区:
其他
文献类型:
--
作者:
Ziye Ma;S. Sojoudi

文献摘要

相似文献

虽然近年来神经网络已被应用于一些系统,但由于缺乏有效的技术来证明其鲁棒性,它们仍然不能用于安全关键系统。在文献中已经提出了一些基于凸优化的技术来研究神经网络的鲁棒性,并且半定规划(SDP)方法已经成为神经网络鲁棒性认证的主要竞争者。SDP方法的主要挑战是它易于产生大的弛豫间隙。在这项工作中,我们通过开发一个顺序框架来解决这个问题,通过将非凸切割添加到通过析取编程的优化问题中,将这个差距缩小到零。我们从理论和经验两方面分析了这种顺序SDP方法的性能,并表明它的桥梁差距的削减数量的增加。
Although neural networks have been applied to several systems in recent years, they still cannot be used in safety-critical systems due to the lack of efficient techniques to certify their robustness. A number of techniques based on convex optimization have been proposed in the literature to study the robustness of neural networks, and the semidefinite programming (SDP) approach has emerged as a leading contender for the robust certification of neural networks. The major challenge to the SDP approach is that it is prone to a large relaxation gap. In this work, we address this issue by developing a sequential framework to shrink this gap to zero by adding non-convex cuts to the optimization problem via disjunctive programming. We analyze the performance of this sequential SDP method both theoretically and empirically, and show that it bridges the gap as the number of cuts increases.