提出高效几何鲁棒性验证方法,提升神经网络对图像变换的可靠性
Certified geometric robustness -- Super-DeepG

- 改进线性松弛与Lipschitz优化推理方式
- 在多个数据集上实现更高精度与更快验证速度
- 适合安全关键场景的模型验证,支持GPU加速
安全关键应用需在正常运行时保持稳定。图像处理任务常要求对微小几何扰动(如旋转、缩放、剪切或平移)具有不变性。本文针对神经网络在图像数据集上的几何扰动鲁棒性,提出形式化验证方法Super-DeepG。该方法改进了线性松弛技术与Lipschitz优化的推理机制,并利用GPU硬件实现高效计算。实验表明,Super-DeepG在保证高精度的同时显著提升验证效率,优于现有方法。代码已开源,发布于GitHub。
原文摘要 · Abstract (English)
Safety-critical applications are required to perform as expected in normal operations. Image processing functions are often required to be insensitive to small geometric perturbations such as rotation, scaling, shearing or translation. This paper addresses the formal verification of neural networks against geometric perturbations on their image dataset. Our method Super-DeepG improves the reasoning used in linear relaxation techniques and Lipschitz optimization, and provides an implementation that leverages GPU hardware. By doing so, Super-DeepG achieves both precision and computational efficiency of robustness certification, to an extent that outperforms prior work. Super-DeepG is shared as an open-source tool on GitHub.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。