An Enhanced MILP-Based Verifier for Adversary Robustness of Neural Networks
摘要
We devise an approach to tackle the problem of neural network robustness certification. We leverage a fast approximate bounding algorithm, which can be parallelized on GPU processors, to efficiently estimate the input range of all neurons in the network. The estimated bounds are then applied to construct a mixed-integer program that transforms the mission of verifying the robustness specification into an optimization problem. We propose several strategies to exploit the information gained from bounding steps to refine and simplify the program formulation. Finally, we evaluate the method on various benchmarks and compare it with some baselines.