Reachability Analysis of Deep Neural Networks with Provable Guarantees

Reachability Analysis of Deep Neural Networks with Provable Guarantees
复制标题

DOI:
10.24963/ijcai.2018/368
复制
发表时间:
2018-05
期刊:
--
影响因子:
--
通讯作者:
Wenjie Ruan;Xiaowei Huang;M. Kwiatkowska
Wenjie Ruan;Xiaowei Huang;M. Kwiatkowska
中科院分区:
其他
文献类型:
--
作者:
Wenjie Ruan;Xiaowei Huang;M. Kwiatkowska

文献摘要

被引文献

相似文献

验证深度神经网络(DNN)的正确性是具有挑战性的。我们研究了前馈DNN的一般可达性问题,对于给定的一组网络输入和输出上的Lipschitz连续函数,计算函数值的上下界。由于网络和函数是Lipschitz连续的,所以在上下界之间的区间内的所有值都是可达的。我们展示了如何通过实例化可达性问题来获得安全验证问题、输出范围分析问题和稳健性度量。针对可达性问题,提出了一种基于自适应嵌套优化的新算法。该技术已在一系列DNN上实施和评估,显示了其效率、可扩展性和处理比最先进的验证方法更广泛的网络类别的能力。
Verifying correctness for deep neural networks (DNNs) is challenging. We study a generic reachability problem for feed-forward DNNs which, for a given set of inputs to the network and a Lipschitz-continuous function over its outputs computes the lower and upper bound on the function values. Because the network and the function are Lipschitz continuous, all values in the interval between the lower and upper bound are reachable. We show how to obtain the safety verification problem, the output range analysis problem and a robustness measure by instantiating the reachability problem. We present a novel algorithm based on adaptive nested optimisation to solve the reachability problem. The technique has been implemented and evaluated on a range of DNNs, demonstrating its efficiency, scalability and ability to handle a broader class of networks than state-of-the-art verification approaches.