Towards Verifying Robustness of Neural Networks Against A Family of Semantic Perturbations
Jeet Mohapatra, Tsui-Wei Weng, Pin-Yu Chen, Sijia Liu, Luca Daniel
Abstract
Verifying robustness of neural networks given a specified threat model is a fundamental yet challenging task. While current verification methods mainly focus on the ℓ p -norm threat model of the input instances, robustness verification against semantic adversarial attacks inducing large ℓ p -norm perturbations, such as color shifting and lighting adjustment, are beyond their capacity. To bridge this gap, we propose Semantify-NN, a model-agnostic and generic robustness verification approach against semantic perturbations for neural networks. By simply inserting our proposed semantic perturbation layers (SP-layers) to the input layer of any given model, Semantify-NN is model-agnostic, and any ℓ p -norm based verification tools can be used to verify the model robustness against semantic perturbations. We illustrate the principles of designing the SP-layers and provide examples including semantic perturbations to image classification in the space of hue, saturation, lightness, brightness, contrast and rotation, respectively. In addition, an efficient refinement technique is proposed to further significantly improve the semantic certificate. Experiments on various network architectures and different datasets demonstrate the superior verification performance of Semantify-NN over ℓ p -norm-based verification frameworks that naively convert semantic perturbation to ℓ p -norm. The results show that Semantify-NN can support robustness verification against a wide range of semantic perturbations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2877178c-9f3a-4ca5-a729-648b4c0fb535Cited by top-tier papers22
- Scalable Certified Segmentation via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevICML 2021 · 49 citations
- Robustness Certification for Point Cloud ModelsTobias Lorenz, Anian Ruoss, Mislav Balunovic, Gagandeep Singh et al.ICCV 2021 · 29 citations
- GSmooth: Certified Robustness against Semantic Transformations via Generalized Randomized SmoothingZhongkai Hao, Chengyang Ying, Yinpeng Dong, Hang Su et al.ICML 2022 · 27 citations
- Efficient Certification of Spatial RobustnessAnian Ruoss, Maximilian Baader, Mislav Balunovic, Martin T. VechevAAAI 2021 · 26 citations
- Exposing previously undetectable faults in deep neural networksIsaac Dunn, Hadrien Pouget, Daniel Kroening, Tom MelhamISSTA 2021 · 25 citations
Builds on1
Related papers
- Precise and Generalized Robustness Certification for Neural NetworksYuanyuan Yuan, Shuai Wang, Zhendong SuUSENIX Security 2023
- Minimally distorted Adversarial Examples with a Fast Adaptive Boundary AttackFrancesco Croce, Matthias HeinICML 2020 · 597 citations
- Scalable Quantitative Verification For Deep Neural NetworksTeodora Baluta, Zheng Leong Chua, Kuldeep S. Meel, Prateek SaxenaICSE 2021 · 39 citations
- CC-CERT: A Probabilistic Approach to Certify General Robustness of Neural NetworksMikhail Pautov, Nurislam Tursynbek, Marina Munkhoeva, Nikita Muravev et al.AAAI 2022 · 27 citations
- Disentangling Safe and Unsafe Image Corruptions via Anisotropy and LocalityRamchandran Muthukumar, Ambar Pal, Jeremias Sulam, René VidalCVPR 2025
