[SAS] Boosting Robustness Verification of Semantic Feature Neighborhoods
Deep neural networks have been shown to be vulnerable to adversarial attacks that perturb inputs based on semantic features. Existing robustness analyzers can reason about semantic feature neighborhoods to increase the networks’ reliability. However, despite the significant progress in these techniques, they still struggle to scale to deep networks and large neighborhoods. In this work, we introduce VeeP, an active learning approach that splits the verification process into a series of smaller verification steps, each is submitted to an existing robustness analyzer. The key idea is to build on prior steps to predict the next optimal step. The optimal step is predicted by estimating the certification velocity and sensitivity via parametric regression. We evaluate VeeP on MNIST, Fashion-MNIST, CIFAR-10 and ImageNet and show that it can analyze neighborhoods of various features: brightness, contrast, hue, saturation, and lightness. We show that, on average, given a 90 minute timeout, VeeP verifies 96% of the maximally certifiable neighborhoods within 29 minutes, while existing splitting approaches verify, on average, 73% of the maximally certifiable neighborhoods within 58 minutes.
Видео [SAS] Boosting Robustness Verification of Semantic Feature Neighborhoods канала ACM SIGPLAN
Видео [SAS] Boosting Robustness Verification of Semantic Feature Neighborhoods канала ACM SIGPLAN
Показать
Комментарии отсутствуют
Информация о видео
Другие видео канала
![Imposter Syndrome, Stupid Questions, and Eight (+/-2) Problems I Need your Help With](https://i.ytimg.com/vi/I5pzeABShv4/default.jpg)
![[POPL'22] The Decidability and Complexity of Interleaved Bidirected Dyck Reachability](https://i.ytimg.com/vi/cMRqpPd3HEE/default.jpg)
![[OCaml'22] Efficient “out of heap” pointers for multicore OCaml](https://i.ytimg.com/vi/eIQf1bRl8_k/default.jpg)
![Warping Cache Simulation of Polyhedral Programs](https://i.ytimg.com/vi/-D0bnastfCA/default.jpg)
![[SLE] Property-Based Testing: Climbing the Stairway to Verification](https://i.ytimg.com/vi/QGOnUm5HBmo/default.jpg)
![[CPP'23] CompCert: a journey through the landscape of mechanized semantics for verified co...](https://i.ytimg.com/vi/9KhagyiGQ_A/default.jpg)
![Low-Latency, High-Throughput Garbage Collection](https://i.ytimg.com/vi/4oizX2MFy5A/default.jpg)
![IRDL: An IR Definition Language for SSA Compilers](https://i.ytimg.com/vi/uKXv1Cc_Pgs/default.jpg)
![[ICFP'22] Safe Couplings: Coupled Refinement Types](https://i.ytimg.com/vi/4LV8a8cz_w0/default.jpg)
![WebRobot: Web Robotic Process Automation using Interactive Programming-by-Demonstration](https://i.ytimg.com/vi/H4mOgIpnWyI/default.jpg)
![[ICFP'22] Beyond Relooper: Recursive Translation of Unstructured Control Flow to Structu…](https://i.ytimg.com/vi/qAeEWKr9wfU/default.jpg)
![Interval Universal Approximation for Neural Networks (Teaser)](https://i.ytimg.com/vi/nuIGJjbc1QE/default.jpg)
![[VMCAI'22] Back to the Future: A Fresh Look at Linear Temporal Logic](https://i.ytimg.com/vi/DSqbfwk2NKg/default.jpg)
![[VMCAI'22] Making PROGRESS in Property Directed Reachability](https://i.ytimg.com/vi/IexW7nvkwwM/default.jpg)
![Natural Language-Guided Programming](https://i.ytimg.com/vi/jhoxJeFeFEI/default.jpg)
![[SLE] Partial Loading of Repository-Based Models through Static Analysis](https://i.ytimg.com/vi/PpVQtfrw6qw/default.jpg)
![Erlang 2021 - Graft: General Purpose Raft Consensus in Elixir](https://i.ytimg.com/vi/7CZFv-d97PQ/default.jpg)
![From Folklore to Fact - Comparing Implementations of Stacks and Continuations](https://i.ytimg.com/vi/wUTgkKPYCZA/default.jpg)
![[PEPM'23] Fast Cryptographic Code via Partial Evaluation](https://i.ytimg.com/vi/ovr9AfpbqhY/default.jpg)
![[GALOP'24] SSA is Freyd Categories](https://i.ytimg.com/vi/CbbQCYS7Q9A/default.jpg)
![[ICFP'22] Staged Compilation with Two-Level Type Theory](https://i.ytimg.com/vi/0BOQE48_qOM/default.jpg)