Reference. Verification of Deep Convolutional Neural Networks Using ImageStars
Convolutional Neural Networks (CNN) have redefined stateof-the-art in many real-world applications, such as facial recognition, image classification, human pose estimation, and semantic segmentation. Despite their success, CNNs are vulnerable to adversarial attacks, where slight changes to their inputs may lead to sharp changes in their output in even well-trained networks. Set-based analysis methods can detect or prove the absence of bounded adversarial attacks, which can then be used to evaluate the effectiveness of neural network training methodology. Unfortunately, existing verification approaches have limited scalability in terms of the size of networks that can be analyzed.
Cite
Cites 48 works (1 here)
With notes (1)
Formal Verification of CNN-based Perception Systems kouvarosFormalVerificationCNNbased2018
We address the problem of verifying neural-based perception systems implemented by convolutional neural networks. We define a notion of local robustness based on affine and photometric transformations. We show the notion cannot be captured by previously employed notions of robustness. The method proposed is based on reachability analysis for feed-forward neural networks and relies on MILP encodings of both the CNNs and transformations under question. We present an implementation and discuss the experimental results obtained for a CNN trained from the MNIST data set.
External (47)
- Formal verification of neural agents in non-deterministic environments (2020)
- Case study: verifying the safety of an autonomous racing car with a neural network controller (2020)
- NNV: The neural network verification tool for deep neural networks and learning-enabled cyber-physical systems (2020)
- Reachable set estimation for neural network control systems: A simulation-guided approach (2020)
- Reachability analysis for feed-forward neural networks using face lattices (2020)
- Optimization and abstraction: A synergistic approach for analyzing neural network robustness (2019)
- Numerical verification of affine systems with up to a billion dimensions (2019)
- Property inference for deep neural networks (2019)
- Reachnn: Reachability analysis of neural-network controlled systems (2019)
- Verisig: verifying safety properties of hybrid systems with neural network controllers (2019)
- The marabou framework for verification and analysis of deep neural networks (2019)
- Robustness verification of classification deep neural networks via linear programming (2019)
- Verification of closed-loop systems with neural network controllers (2019)
- An abstract domain for certifying neural networks (2019)
- Reachability analysis for neural feedback systems using regressive polynomial rule inference (2019)
- Formal verification of neural network controlled autonomous systems (2019)
- Safety verification of cyber-physical systems with reinforcement learning control (2019)
- Parallelizable reachability analysis algorithms for feed-forward neural networks (2019)
- Star-based reachability analsysis for deep neural networks (2019)
- Reachability analysis for high-index linear differential algebraic equations (daes) (2019)
- A game-based approximate verification of deep neural networks with provable guarantees (2019)
- Specification-guided safety verification for feedforward neural networks (2019)
- A dual approach to scalable verification of deep networks (2018)
- Ai2: Safety and robustness certification of neural networks with abstract interpretation (2018)
- Global robustness evaluation of deep neural networks with provable guarantees for the l_0 norm (2018)
- Fast and effective robustness certification (2018)
- Formal security analysis of neural networks using symbolic intervals (2018)
- Towards fast computation of certified robustness for relu networks (2018)
- Output reachable set estimation and verification for multilayer neural networks (2018)
- Reachable set estimation and safety verification for piecewise linear systems with neural network controllers (2018)
- Efficient neural network robustness certification with general activation functions (2018)
- Simulation-equivalent reachability of large linear systems with inputs (2017)
- Output range analysis for deep neural networks (2017)
- Formal guarantees on the robustness of a classifier against adversarial manipulation (2017)
- Reluplex: An efficient smt solver for verifying deep neural networks (2017)
- An approach to reachability analysis for feed-forward relu neural networks (2017)
- Foolbox v0.8.0: A python toolbox to benchmark the robustness of machine learning models (2017)
- Provable defenses against adversarial examples via the convex outer adversarial polytope (2017)
- Reachable set computation and safety verification for neural networks with relu activations (2017)
- Deepfool: a simple and accurate method to fool deep neural networks (2016)
- Matconvnet: Convolutional neural networks for matlab (2015)
- Explaining and harnessing adversarial examples (2014)
- Very deep convolutional networks for large-scale image recognition (2014)
- Imagenet classification with deep convolutional neural networks (2012)
- The mnist database of handwritten digits (1998)
- Gradient-based learning applied to document recognition (1998)
- Face recognition: A convolutional neural-network approach (1997)