arXiv:2411.04594cs.LGcs.AI2024-11AAAI被引 5

提出高效验证神经网络对模糊锐化等卷积扰动的鲁棒性方法。

Verification of Neural Networks against Convolutional Perturbations via Parameterised Kernels

  • 用可参数化的卷积核建模相机抖动、模糊等扰动,控制强度并保持性质。
  • 通过线性层预处理输入,实现紧致边界,在标准基准上获得安全证书。
  • 首次解决特定卷积扰动(如相机抖动)的可验证鲁棒性问题,适合安全关键场景。

我们提出一种高效验证神经网络对抗卷积扰动(如模糊或锐化)的方法。采用已知的相机抖动、盒式模糊和锐化核定义输入扰动,并将其线性参数化,可在保持核特性的同时调节扰动强度。为便于在神经网络验证中应用,我们开发了一种高效的参数化核卷积方法。该卷积结果可通过在原网络前添加线性层编码为验证输入,从而生成紧致的边界并显著提升验证效率。进一步引入输入分割作为分支定界策略以增强精度。实验表明,该方法在多个标准基准上实现了基线无法提供安全证书的鲁棒性验证。据我们所知,这是首个针对相机抖动等特定卷积扰动的可验证鲁棒性解决方案。

原文摘要 · Abstract (English)

We develop a method for the efficient verification of neural networks against convolutional perturbations such as blurring or sharpening. To define input perturbations we use well-known camera shake, box blur and sharpen kernels. We demonstrate that these kernels can be linearly parameterised in a way that allows for a variation of the perturbation strength while preserving desired kernel properties. To facilitate their use in neural network verification, we develop an efficient way of convolving a given input with these parameterised kernels. The result of this convolution can be used to encode the perturbation in a verification setting by prepending a linear layer to a given network. This leads to tight bounds and a high effectiveness in the resulting verification step. We add further precision by employing input splitting as a branch and bound strategy. We demonstrate that we are able to verify robustness on a number of standard benchmarks where the baseline is unable to provide any safety certificates. To the best of our knowledge, this is the first solution for verifying robustness against specific convolutional perturbations such as camera shake.

神经网络验证卷积扰动鲁棒性安全认证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。