arXiv:2410.06816cs.LGcs.AI2024-10被引 5

揭示多神经元松弛在神经网络认证中的表达极限与突破路径

Expressiveness of Multi-Neuron Convex Relaxations in Neural Network Certification

  • 首次严格分析多神经元松弛的表达能力,发现其仍不完整
  • 证明即使优化所有神经元,仍存在普遍凸性障碍
  • 提出通过增加神经元或划分输入域实现完全认证,适合验证研究者

神经网络认证方法依赖凸松弛提供鲁棒性保障,但现有松弛常不精确:即使最准确的单神经元松弛对一般ReLU网络也存在不完备性,这一现象称为‘单神经元凸性屏障’。尽管多神经元松弛被启发式应用以解决此问题,但两个核心问题仍未解答:(i) 是否能突破该屏障?(ii) 是否具有超越单神经元松弛的理论能力?本文首次对多神经元松弛的表达能力进行严格分析。出人意料的是,我们证明即使在最优配置下捕捉有限数量的神经元与层,多神经元松弛依然本质不完备,从而将单神经元屏障扩展为神经网络认证的‘普遍凸性屏障’。正面结果是,通过(1)增加多项式数量的精心设计的ReLU神经元,或(2)将输入域划分为凸子多面体,可实现完整性。这使多神经元松弛区别于无法实现前者的单神经元方法,且后者在划分复杂度上更差。本研究为多神经元松弛奠定基础,并指明新方向,包括面向多神经元松弛的训练方法及以之为核心的验证技术。

原文摘要 · Abstract (English)

Neural network certification methods heavily rely on convex relaxations to provide robustness guarantees. However, these relaxations are often imprecise: even the most accurate single-neuron relaxation is incomplete for general ReLU networks, a limitation known as the *single-neuron convex barrier*. While multi-neuron relaxations have been heuristically applied to address this issue, two central questions arise: (i) whether they overcome the convex barrier, and if not, (ii) whether they offer theoretical capabilities beyond those of single-neuron relaxations. In this work, we present the first rigorous analysis of the expressiveness of multi-neuron relaxations. Perhaps surprisingly, we show that they are inherently incomplete, even when allocated sufficient resources to capture finitely many neurons and layers optimally. This result extends the single-neuron barrier to a *universal convex barrier* for neural network certification. On the positive side, we show that completeness can be achieved by either (i) augmenting the network with a polynomial number of carefully designed ReLU neurons or (ii) partitioning the input domain into convex sub-polytopes, thereby distinguishing multi-neuron relaxations from single-neuron ones which are unable to realize the former and have worse partition complexity for the latter. Our findings establish a foundation for multi-neuron relaxations and point to new directions for certified robustness, including training methods tailored to multi-neuron relaxations and verification methods with multi-neuron relaxations as the main subroutine.

神经网络认证凸松弛鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。