Reducing DNN Properties to Enable Falsification with Adversarial Attacks

Reducing DNN Properties to Enable Falsification with Adversarial Attacks
复制标题

DOI:
10.1109/icse43902.2021.00036
复制
发表时间:
2021-05
期刊:
2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE)
影响因子:
--
通讯作者:
David Shriver;Sebastian G. Elbaum;Matthew B. Dwyer
David Shriver;Sebastian G. Elbaum;Matthew B. Dwyer
中科院分区:
其他
文献类型:
--
作者:
David Shriver;Sebastian G. Elbaum;Matthew B. Dwyer

文献摘要

被引文献

相似文献

深度神经网络(DNN)越来越多地被部署在安全关键领域,从自动驾驶汽车到医疗设备,在这些领域,错误的后果需要能够提供更强的行为保证的技术,而不仅仅是高测试精度。本文探讨了扩大现有对抗性攻击技术在DNN安全属性伪造中的应用。我们认为并在后来证明,此类攻击为财产伪造提供了强大的可扩展算法库。为了使证伪的广泛应用,我们引入了一个语义保持减少的多个安全属性类型,这suburbances先前的工作,到一组等价的正确性问题,适合对抗性攻击。我们评估了我们的减少方法作为一系列DNN正确性问题的伪造的推动者,并展示了其成本效益和可扩展性。
Deep Neural Networks (DNN) are increasingly being deployed in safety-critical domains, from autonomous vehicles to medical devices, where the consequences of errors demand techniques that can provide stronger guarantees about behavior than just high test accuracy. This paper explores broadening the application of existing adversarial attack techniques for the falsification of DNN safety properties. We contend and later show that such attacks provide a powerful repertoire of scalable algorithms for property falsification. To enable the broad application of falsification, we introduce a semantics-preserving reduction of multiple safety property types, which subsume prior work, into a set of equivalid correctness problems amenable to adversarial attacks. We evaluate our reduction approach as an enabler of falsification on a range of DNN correctness problems and show its cost-effectiveness and scalability.