arXiv:2512.06010cs.CV2025-12被引 1

提出首个实时可运行的语义分割鲁棒性认证方法,基于利普希茨约束实现高效验证。

Fast and Flexible Robustness Certificates for Semantic Segmentation

  • 采用内置利普希茨约束的网络结构,支持快速训练与认证。
  • 在Cityscapes上达到竞争性像素准确率,认证速度比随机平滑快600倍。
  • 适用于自动驾驶等对安全性和实时性要求高的场景。

深度神经网络对微小扰动敏感,可能导致感知不变输入下的预测结果剧变。现有对抗鲁棒性研究多聚焦分类任务,语义分割的高效认证方法稀缺。本文提出一类新型可认证鲁棒的语义分割网络,内置利普希茨约束,训练高效,在Cityscapes等挑战性数据集上达到有竞争力的像素准确率。我们构建了通用的语义分割鲁棒性认证框架,展示利普希茨网络在灵活性与计算效率上的优势。该方法首次实现真正意义上的实时可运行认证,支持在ℓ₂攻击半径ε下计算多种性能指标的最差表现。实验表明,其认证过程在NVIDIA A100 GPU上比随机平滑快约600倍,且证书质量相当。进一步对比最新对抗攻击验证了证书的紧致性。

原文摘要 · Abstract (English)

Deep Neural Networks are vulnerable to small perturbations that can drastically alter their predictions for perceptually unchanged inputs. The literature on adversarially robust Deep Learning attempts to either enhance the robustness of neural networks (e.g, via adversarial training) or to certify their decisions up to a given robustness level (e.g, by using randomized smoothing, formal methods or Lipschitz bounds). These studies mostly focus on classification tasks and few efficient certification procedures currently exist for semantic segmentation. In this work, we introduce a new class of certifiably robust Semantic Segmentation networks with built-in Lipschitz constraints that are efficiently trainable and achieve competitive pixel accuracy on challenging datasets such as Cityscapes. Additionally, we provide a novel framework that generalizes robustness certificates for semantic segmentation tasks, where we showcase the flexibility and computational efficiency of using Lipschitz networks. Our approach unlocks real-time compatible certifiably robust semantic segmentation for the first time. Moreover, it allows the computation of worst-case performance under $\ell_2$ attacks of radius $ε$ across a wide range of performance measures. Crucially, we benchmark the runtime of our certification process and find our approach to be around 600 times faster than randomized smoothing methods at inference with comparable certificates on an NVIDIA A100 GPU. Finally, we evaluate the tightness of our worstcase certificates against state-of-the-art adversarial attacks to further validate the performance of our method.

语义分割鲁棒性认证利普希茨实时推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。