Verification of Deep Convolutional Neural Networks Using ImageStars

Verification of Deep Convolutional Neural Networks Using ImageStars
复制标题

DOI:
10.1007/978-3-030-53288-8_2
复制
发表时间:
2020-06-13
期刊:
Computer Aided Verification
影响因子:
--
通讯作者:
Johnson TT
Johnson TT
中科院分区:
其他
文献类型:
--
作者:
Tran HD;Bak S;Xiang W;Johnson TT

文献摘要

参考文献

被引文献

相似文献

卷积神经网络(CNN)在人脸识别、图像分类、人体姿态估计和语义分割等许多实际应用中重新定义了最先进的技术。尽管CNN取得了成功,但它们很容易受到对手攻击,在这种攻击中,即使是训练有素的网络,其输入的微小变化也可能导致其输出的急剧变化。基于集合的分析方法可以检测或证明没有有界对抗性攻击,然后可以用来评估神经网络训练方法的有效性。遗憾的是,现有的验证方法在可分析的网络大小方面具有有限的可扩展性。在本文中,我们描述了一个基于集合的框架,它成功地处理了在ImageNet上具有高准确度的真实CNN,如VGG16和VGG19。我们的方法基于一种新的集合表示,称为ImageStar,它能够对CNN进行高效、准确和过近似的分析。ImageStars通过将具体图像上的操作与线性规划(LP)相结合来执行高效的基于集合的分析。我们的方法是在一个名为NNV的工具中实现的,它可以验证VGG网络相对于一小部分输入状态的健壮性,这些输入状态来自对抗性攻击,如DeepFool攻击。实验结果表明,我们的方法比现有的带状和多面体方法具有更少的保守性和更快的速度。
Convolutional Neural Networks (CNN) have redefined state-of-the-art in many real-world applications, such as facial recognition, image classification, human pose estimation, and semantic segmentation. Despite their success, CNNs are vulnerable to adversarial attacks, where slight changes to their inputs may lead to sharp changes in their output in even well-trained networks. Set-based analysis methods can detect or prove the absence of bounded adversarial attacks, which can then be used to evaluate the effectiveness of neural network training methodology. Unfortunately, existing verification approaches have limited scalability in terms of the size of networks that can be analyzed. In this paper, we describe a set-based framework that successfully deals with real-world CNNs, such as VGG16 and VGG19, that have high accuracy on ImageNet. Our approach is based on a new set representation called the ImageStar, which enables efficient exact and over-approximative analysis of CNNs. ImageStars perform efficient set-based analysis by combining operations on concrete images with linear programming (LP). Our approach is implemented in a tool called NNV, and can verify the robustness of VGG networks with respect to a small set of input states, derived from adversarial attacks, such as the DeepFool attack. The experimental results show that our approach is less conservative and faster than existing zonotope and polytope methods.
DOI: 10.1109/72.554195
发表时间: 1997-01-01
影响因子: --
作者:
Lawrence, S;Giles, CL;Back, AD
通讯作者: Back, AD
DOI: 10.1007/978-3-030-53288-8_2
发表时间: 2020-06-13
期刊: Computer Aided Verification
影响因子: --
作者:
Tran HD;Bak S;Xiang W;Johnson TT
通讯作者: Johnson TT
DOI: 10.1145/3358228
发表时间: 2019-10-01
影响因子: 2
作者:
Huang, Chao;Fan, Jiameng;Zhu, Qi
通讯作者: Zhu, Qi
DOI: 10.1145/3358230
发表时间: 2019-10-01
影响因子: 2
作者:
Hoang-Dung Tran;Cai, Feiyang;Koutsoukos, Xenofon
通讯作者: Koutsoukos, Xenofon
DOI: 10.1145/3065386
发表时间: 2017-06-01
影响因子: 22.7
作者:
Krizhevsky, Alex;Sutskever, Ilya;Hinton, Geoffrey E.
通讯作者: Hinton, Geoffrey E.