提出新方法提升神经网络验证速度,识别何时模板共享无效。
Uncovering the Limits of Proof Sharing for Neural Networks
- 用联合稳定神经元指标分析模板共享效果差异
- 在多个任务上平均提速1.13倍,避免无效模板使用
- 适合关注验证效率与可靠性研究者
神经网络鲁棒性验证在关键领域日益重要。某些场景下,通过复用中间层抽象状态(即模板)可加速不完全验证方法。然而,模板加速在不同网络结构、属性、数据集和训练方法下的有效性仍不确定。本文系统研究模板加速的极限,发现模板包含率在不同情况下差异显著。我们提出联合稳定神经元的新度量来解释该现象,表明某些情况下模板几乎不可能带来加速。为此,我们提出FastCert:一种自动分配模板至网络各层的新型技术,若模板预计无法提速则直接舍弃。在基于覆盖设计的大量$L_0$-验证任务中,FastCert相较现有模板重用技术平均提速1.13倍。
原文摘要 · Abstract (English)
Robustness verification of neural networks is increasingly important, due to their use in many critical domains. In certain scenarios, proof sharing has been shown to accelerate incomplete verification techniques by reusing intermediate-layer abstract states, or templates, across queries. However, questions remain as to the robustness of template-based acceleration across varying network architectures, properties, datasets, and training methods. In this work, we perform a systematic study of the effectiveness of template-based acceleration and its limits. Our study shows that template subsumption rates can vary widely across scenarios. We present a novel metric of jointly stable neurons to explain this variation, showing that in some cases template-based techniques are very unlikely to provide any speedup. Then, we present FastCert, a novel technique for automatically distributing templates across neural network layers to increase performance impact, eschewing templates entirely if they are unlikely to produce a speedup. Across a large set of covering-design based $L_0$-verification tasks, FastCert achieved an average speedup of 1.13x over an extant template-based reuse technique.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。