提出可扩展的鲁棒性验证框架,提升高维分割模型的安全保障能力。
Probabilistic Robustness Analysis in High Dimensional Space: Application to Semantic Segmentation Network
- 基于置信区间与剪裁块技术,实现对高维输入输出的可证明鲁棒性分析。
- 在多个数据集上验证,相比现有方法保守性显著降低,安全保证更可靠。
- 适用于医疗影像、自动驾驶等关键场景,支持代码开源复现。
语义分割网络(SSNs)在医学影像和自动驾驶等安全关键应用中至关重要,其在不确定性下的鲁棒性尤为关键。然而,现有概率验证方法难以适应现代分割任务的复杂性和高维特性,导致保证过于保守且实用性有限。本文提出一种架构无关、可扩展至高维输入输出空间的概率验证框架。该方法结合增强型共形推断(CI),引入名为‘剪裁块’(clipping block)的新技术,在提供可证明保证的同时缓解了先前方法的过度保守问题。在CamVid、OCTA-500、Lung Segmentation和Cityscapes等多个大规模分割模型上的实验表明,该框架在保持可靠安全保证的同时,相较当前最优方法显著降低了保守性。我们还公开了代码仓库(https://github.com/Navidhashemicodes/SSN_Reach_CLP_Surrogate),以支持研究复现。
原文摘要 · Abstract (English)
Semantic segmentation networks (SSNs) are central to safety-critical applications such as medical imaging and autonomous driving, where robustness under uncertainty is essential. However, existing probabilistic verification methods often fail to scale with the complexity and dimensionality of modern segmentation tasks, producing guarantees that are overly conservative and of limited practical value. We propose a probabilistic verification framework that is architecture-agnostic and scalable to high-dimensional input-output spaces. Our approach employs conformal inference (CI), enhanced by a novel technique that we call the \textbf{clipping block}, to provide provable guarantees while mitigating the excessive conservatism of prior methods. Experiments on large-scale segmentation models across CamVid, OCTA-500, Lung Segmentation, and Cityscapes demonstrate that our framework delivers reliable safety guarantees while substantially reducing conservatism compared to state-of-the-art approaches on segmentation tasks. We also provide a public GitHub repository (https://github.com/Navidhashemicodes/SSN_Reach_CLP_Surrogate) for this approach, to support reproducibility.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。