Reference. Provable repair of deep neural networks

Deep Neural Networks (DNNs) have grown in popularity over the past decade and are now being used in safety-critical domains such as aircraft collision avoidance. This has motivated a large number of techniques for finding unsafe behavior in DNNs. In contrast, this paper tackles the problem of correcting a DNN once unsafe behavior is found. We introduce the provable repair problem, which is the problem of repairing a network N to construct a new network N′ that satisfies a given specification. If the safety specification is over a finite set of points, our Provable Point Repair algorithm can find a provably minimal repair satisfying the specification, regardless of the activation functions used. For safety specifications addressing convex polytopes containing infinitely many points, our Provable Polytope Repair algorithm can find a provably minimal repair satisfying the specification for DNNs using piecewise-linear activation functions. The key insight behind both of these algorithms is the introduction of a Decoupled DNN architecture, which allows us to reduce provable repair to a linear programming problem. Our experimental results demonstrate the efficiency and effectiveness of our Provable Repair algorithms on a variety of challenging tasks.

Cite

Cite as @sotoudehProvableRepairDeep2021 (helia, typst) · \cite{sotoudehProvableRepairDeep2021} (LaTeX)
BibTeX
bibtex · 15 lines
@inproceedings{sotoudehProvableRepairDeep2021,
 title = {Provable Repair of Deep Neural Networks},
 author = {Sotoudeh, Matthew and Thakur, Aditya V.},
 date = {2021-06-19},
 isbn = {978-1-4503-8391-2},
 doi = {10.1145/3453483.3454064},
 url = {https://dl.acm.org/doi/10.1145/3453483.3454064},
 urldate = {2023-11-27},
 booktitle = {Proceedings of the 42nd {{ACM SIGPLAN International Conference}} on {{Programming Language Design}} and {{Implementation}}},
 pages = {588--603},
 publisher = {ACM},
 langid = {english},
 eventtitle = {{{PLDI}} '21: 42nd {{ACM SIGPLAN International Conference}} on {{Programming Language Design}} and {{Implementation}}},
 location = {Virtual Canada}
}
hayagriva YAML (typst)
yaml · 23 lines
sotoudehProvableRepairDeep2021:
  type: article
  title: Provable Repair of Deep Neural Networks
  author:
  - Sotoudeh, Matthew
  - Thakur, Aditya V.
  date: 2021-06-19
  page-range: 588-603
  url:
    value: https://dl.acm.org/doi/10.1145/3453483.3454064
    date: 2023-11-27
  serial-number:
    doi: 10.1145/3453483.3454064
    isbn: 978-1-4503-8391-2
  language: en-US
  parent:
  - type: proceedings
    title: Proceedings of the 42nd {ACM SIGPLAN International Conference} on {Programming Language Design} and {Implementation}
    publisher:
      name: ACM
      location: Virtual Canada
  - type: conference
    title: '{PLDI} ''21: 42nd {ACM SIGPLAN International Conference} on {Programming Language Design} and {Implementation}'
Cited by (1)

Architecture-Preserving Provable Repair of Deep Neural Networks taoArchitecturePreservingProvableRepair2023

Deep neural networks (DNNs) are becoming increasingly important components of software, and are considered the state-of-the-art solution for a number of problems, such as image recognition. However, DNNs are far from infallible, and incorrect behavior of DNNs can have disastrous real-world consequences. This paper addresses the problem of architecture-preserving V-polytope provable repair of DNNs. A V-polytope defines a convex bounded polytope using its vertex representation. V-polytope provable repair guarantees that the repaired DNN satisfies the given specification on the infinite set of points in the given V-polytope. An architecture-preserving repair only modifies the parameters of the DNN, without modifying its architecture. The repair has the flexibility to modify multiple layers of the DNN, and runs in polynomial time. It supports DNNs with activation functions that have some linear pieces, as well as fully-connected, convolutional, pooling and residual layers. To the best our knowledge, this is the first provable repair approach that has all of these features. We implement our approach in a tool called APRNN. Using MNIST, ImageNet, and ACAS Xu DNNs, we show that it has better efficiency, scalability, and generalization compared to PRDNN and REASSURE, prior provable repair methods that are not architecture preserving. CCS Concepts: • Computing methodologies → Neural networks; • Theory of computation → Linear programming; • Software and its engineering → Software post-development issues.
PDF · DOI · pldb
Cites 61 works (0 here)
External (61)
sotoudehProvableRepairDeep2021 reference entries/refs/sotoudehProvableRepairDeep2021/sotoudehProvableRepairDeep2021.hel