Towards Proving the Adversarial Robustness of Deep Neural Networks

Towards Proving the Adversarial Robustness of Deep Neural Networks
复制标题

DOI:
10.4204/eptcs.257.3
复制
发表时间:
2017-01-01
影响因子:
--
通讯作者:
Kochenderfer, Mykel J.
Kochenderfer, Mykel J.
中科院分区:
其他
文献类型:
--
作者:
Katz, Guy;Barrett, Clark;Kochenderfer, Mykel J.

文献摘要

被引文献

相似文献

自动驾驶汽车是高度复杂的系统,需要在各种情况下可靠地发挥作用。为这些车辆手工制作软件控制器是困难的,但在使用通过机器学习产生的深度神经网络方面已经取得了一些成功。然而,深度神经网络对人类工程师来说是不透明的,这使得他们的正确性很难得到证明;而且现有的自动化技术并不是为在神经网络上操作而设计的,无法扩展到大型系统。本文的重点是证明深层神经网络的对抗稳健性,即证明对正确分类的网络输入的微小扰动不会导致其错误分类。我们描述了我们最近和正在进行的一些关于验证网络的对抗性健壮性的工作,并讨论了我们遇到的一些公开问题以及如何解决这些问题。
Autonomous vehicles are highly complex systems, required to function reliably in a wide variety of situations. Manually crafting software controllers for these vehicles is difficult, but there has been some success in using deep neural networks generated usingmachine-learning. However, deep neural networks are opaque to human engineers, rendering their correctness very difficult to provemanually; and existing automated techniques, which were not designed to operate on neural networks, fail to scale to large systems. This paper focuses on proving the adversarial robustness of deep neural networks, i.e. proving that small perturbations to a correctly-classified input to the network cannot cause it to be misclassified. We describe some of our recent and ongoing work on verifying the adversarial robustness of networks, and discuss some of the open questions we have encountered and how they might be addressed.