Neural Network Robustness as a Verification Property: A Principled Case Study

Neural Network Robustness as a Verification Property: A Principled Case Study
复制标题

DOI:
10.1007/978-3-031-13185-1_11
复制
发表时间:
2021-04
期刊:
ArXiv
影响因子:
--
通讯作者:
Marco Casadio;Ekaterina Komendantskaya;M. Daggitt;Wen Kokke;Guy Katz;Guy Amir;Idan Refaeli
Marco Casadio;Ekaterina Komendantskaya;M. Daggitt;Wen Kokke;Guy Katz;Guy Amir;Idan Refaeli
中科院分区:
其他
文献类型:
--
作者:
Marco Casadio;Ekaterina Komendantskaya;M. Daggitt;Wen Kokke;Guy Katz;Guy Amir;Idan Refaeli

文献摘要

被引文献

相似文献

神经网络在检测噪声数据中的模式方面非常成功,并已成为许多领域的首选技术。然而,它们的有用性受到它们对对抗性攻击的敏感性的阻碍。最近,已经提出了许多用于测量和提高网络对对抗性扰动的鲁棒性的方法,并且这种不断增长的研究已经产生了许多明确或隐含的鲁棒性概念。这些概念之间的联系往往是微妙的,它们之间的系统比较在文献中缺失。在本文中,我们开始解决这一差距,建立一般原则的经验分析和评估网络的鲁棒性作为一个数学属性,在网络的训练阶段,其验证,并在其部署。然后,我们应用这些原则,并进行案例研究,展示我们的一般方法的实际好处。
Neural networks are very successful at detecting patterns in noisy data, and have become the technology of choice in many fields. However, their usefulness is hampered by their susceptibility toadversarial attacks. Recently, many methods for measuring and improving a network’s robustness to adversarial perturbations have been proposed, and this growing body of research has given rise to numerous explicit or implicit notions of robustness. Connections between these notions are often subtle, and a systematic comparison between them is missing in the literature. In this paper we begin addressing this gap, by setting up general principles for the empirical analysis and evaluation of a network’s robustness as a mathematical property—during the network’s training phase, its verification, and after its deployment. We then apply these principles and conduct a case study that showcases the practical benefits of our general approach.