Robustness certification with generative models
Matthew Mirman, Alexander Hägele, Pavol Bielik, Timon Gehr, Martin T. Vechev
Abstract
Generative neural networks are powerful models capable of learning a wide range of rich semantic image transformations such as altering person's age, head orientation, adding mustache, changing the hair color and many more. At a high level, a generative model effectively produces new and previously unseen images with the desired properties, which can then be used to improve the accuracy of existing models. In this work, we advance the state-of-the-art in verification by bridging the gap between (i) the well studied but limited norm-based and geometric transformations, and (ii) the rich set of semantic transformations used in practice. This problem is especially hard since the images are generated from a highly non-convex image manifold, preventing the use of most existing verifiers, which often rely on convex relaxations. We present a new verifier, called GenProve, which is capable of certifying the rich set of semantic transformations of generative models. GenProve can provide both sound deterministic and probabilistic guarantees, by capturing infinite non-convex sets of activation vectors and distributions over them, while scaling to realistic networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4e530564-6ac2-46c1-88fa-f669dfca43afCited by top-tier papers6
- Learning from Uncertain Data: From Possible Worlds to Possible ModelsJiongli Zhu, Su Feng, Boris Glavic, Babak SalimiNeurIPS 2024 · 4 citations
- Precise and Generalized Robustness Certification for Neural NetworksYuanyuan Yuan, Shuai Wang, Zhendong SuUSENIX Security 2023
- SoK: Certified Robustness for Deep Neural NetworksLinyi Li, Tao Xie, Bo LiS&P 2023
- Certifying Adversarial Robustness of Quantum Classifiers under Known-Readout Query AccessJi Guan, Mingyu HuangCCS 2026
- Efficient Verification of Neural Networks Against LVM-Based SpecificationsHarleen Hanspal, Alessio LomuscioCVPR 2023
Builds on2
- Certified Robustness to Adversarial Examples with Differential PrivacyMathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu et al.S&P 2019 · 1,022 citations
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov et al.S&P 2018 · 987 citations
Related papers
- Towards Verifying Robustness of Neural Networks Against A Family of Semantic PerturbationsJeet Mohapatra, Tsui-Wei Weng, Pin-Yu Chen, Sijia Liu et al.CVPR 2020
- Provable Defense Against Geometric TransformationsRem Yang, Jacob Laurel, Sasa Misailovic, Gagandeep SinghICLR 2023 · 1 citation
- Provably Robust Adversarial ExamplesDimitar Iliev Dimitrov, Gagandeep Singh, Timon Gehr, Martin T. VechevICLR 2022 · 12 citations
- GSmooth: Certified Robustness against Semantic Transformations via Generalized Randomized SmoothingZhongkai Hao, Chengyang Ying, Yinpeng Dong, Hang Su et al.ICML 2022 · 27 citations
- Overcoming the Convex Barrier for Simplex InputsHarkirat Singh Behl, M. Pawan Kumar, Philip H. S. Torr, Krishnamurthy DvijothamNeurIPS 2021 · 7 citations
