Provable repair of deep neural networks

Provable repair of deep neural networks
复制标题

DOI:
10.1145/3453483.3454064
复制
发表时间:
2021-04
期刊:
Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation
影响因子:
--
通讯作者:
Matthew Sotoudeh;Aditya V. Thakur
Matthew Sotoudeh;Aditya V. Thakur
中科院分区:
其他
文献类型:
--
作者:
Matthew Sotoudeh;Aditya V. Thakur

文献摘要

被引文献

相似文献

深度神经网络(DNN)在过去十年中变得越来越流行,目前正被用于飞机碰撞避免等安全关键领域。这激发了大量用于在DNN中发现不安全行为的技术。相反,本文解决的是一旦发现不安全行为就纠正DNN的问题。我们引入了可证明修复问题,即修复一个网络N以构造一个满足给定规范的新网络N‘的问题。如果安全规范在一个有限的点集合上,我们的可证明点修复算法可以找到满足该规范的可证明的最小修复,而不考虑所使用的激活函数。对于包含无穷多个点的凸多面体的安全规范,我们的可证明多面体修复算法可以使用分段线性激活函数找到满足DNN规范的可证明最小修复。这两个算法背后的关键洞察力是引入了去耦合的DNN体系结构,它允许我们将可证明修复减少到线性规划问题。我们的实验结果证明了我们的可证明修复算法在各种具有挑战性的任务上的效率和有效性。
Deep Neural Networks (DNNs) have grown in popularity over the past decade and are now being used in safety-critical domains such as aircraft collision avoidance. This has motivated a large number of techniques for finding unsafe behavior in DNNs. In contrast, this paper tackles the problem of correcting a DNN once unsafe behavior is found. We introduce the provable repair problem, which is the problem of repairing a network N to construct a new network N′ that satisfies a given specification. If the safety specification is over a finite set of points, our Provable Point Repair algorithm can find a provably minimal repair satisfying the specification, regardless of the activation functions used. For safety specifications addressing convex polytopes containing infinitely many points, our Provable Polytope Repair algorithm can find a provably minimal repair satisfying the specification for DNNs using piecewise-linear activation functions. The key insight behind both of these algorithms is the introduction of a Decoupled DNN architecture, which allows us to reduce provable repair to a linear programming problem. Our experimental results demonstrate the efficiency and effectiveness of our Provable Repair algorithms on a variety of challenging tasks.