Architecture-Preserving Provable Repair of Deep Neural Networks

Architecture-Preserving Provable Repair of Deep Neural Networks
复制标题

DOI:
10.1145/3591238
复制
发表时间:
2023-04
影响因子:
--
通讯作者:
Zhe Tao;Stephanie Nawas;Jacqueline Mitchell;Aditya V. Thakur
Zhe Tao;Stephanie Nawas;Jacqueline Mitchell;Aditya V. Thakur
中科院分区:
--
文献类型:
--
作者:
Zhe Tao;Stephanie Nawas;Jacqueline Mitchell;Aditya V. Thakur

文献摘要

相似文献

深度神经网络(dnn)正在成为软件中越来越重要的组成部分,并且被认为是许多问题的最先进的解决方案,例如图像识别。然而,深度神经网络远非万无一失,深度神经网络的错误行为可能会对现实世界造成灾难性的后果。本文研究了dnn的保结构v -多面体可证明修复问题。一个v型多面体使用它的顶点表示来定义一个凸有界多面体。v -多面体可证明修复保证修复后的DNN在给定v -多面体的无穷点集上满足给定规范。保留结构的修复只修改深度神经网络的参数,而不修改其结构。修复具有修改DNN多层的灵活性,并且在多项式时间内运行。它支持具有一些线性部分的激活函数的dnn,以及全连接,卷积,池化和残差层。据我们所知,这是第一个具有所有这些特征的可证明的修复方法。我们在一个叫做APRNN的工具中实现了我们的方法。通过使用MNIST、ImageNet和ACAS Xu dnn,我们证明了与PRDNN和assure相比,它具有更好的效率、可扩展性和泛化性。
Deep neural networks (DNNs) are becoming increasingly important components of software, and are considered the state-of-the-art solution for a number of problems, such as image recognition. However, DNNs are far from infallible, and incorrect behavior of DNNs can have disastrous real-world consequences. This paper addresses the problem of architecture-preserving V-polytope provable repair of DNNs. A V-polytope defines a convex bounded polytope using its vertex representation. V-polytope provable repair guarantees that the repaired DNN satisfies the given specification on the infinite set of points in the given V-polytope. An architecture-preserving repair only modifies the parameters of the DNN, without modifying its architecture. The repair has the flexibility to modify multiple layers of the DNN, and runs in polynomial time. It supports DNNs with activation functions that have some linear pieces, as well as fully-connected, convolutional, pooling and residual layers. To the best our knowledge, this is the first provable repair approach that has all of these features. We implement our approach in a tool called APRNN. Using MNIST, ImageNet, and ACAS Xu DNNs, we show that it has better efficiency, scalability, and generalization compared to PRDNN and REASSURE, prior provable repair methods that are not architecture preserving.