We devise an approach to tackle the problem of neural network robustness certification. We leverage a fast approximate bounding algorithm, which can be parallelized on GPU processors, to efficiently estimate the input range of all neurons in the network. The estimated bounds are then applied to construct a mixed-integer program that transforms the mission of verifying the robustness specification into an optimization problem. We propose several strategies to exploit the information gained from bounding steps to refine and simplify the program formulation. Finally, we evaluate the method on various benchmarks and compare it with some baselines.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An Enhanced MILP-Based Verifier for Adversary Robustness of Neural Networks

  • Shaocong Han,
  • Jingwei Ge,
  • Yuchen Shi,
  • Yi Zhang

摘要

We devise an approach to tackle the problem of neural network robustness certification. We leverage a fast approximate bounding algorithm, which can be parallelized on GPU processors, to efficiently estimate the input range of all neurons in the network. The estimated bounds are then applied to construct a mixed-integer program that transforms the mission of verifying the robustness specification into an optimization problem. We propose several strategies to exploit the information gained from bounding steps to refine and simplify the program formulation. Finally, we evaluate the method on various benchmarks and compare it with some baselines.