Hierarchical Verification for Adversarial Robustness
Cong Han Lim, Raquel Urtasun, Ersin Yumer
Abstract
We introduce a new framework for the exact point-wise robustness verification problem that exploits the layer-wise geometric structure of deep feed-forward networks with rectified linear activations (ReLU networks). The activation regions of the network partition the input space, and one can verify the robustness around a point by checking all the activation regions within the desired radius. The GeoCert algorithm (Jordan et al., NeurIPS 2019) treats this partition as a generic polyhedral complex in order to detect which region to check next. In contrast, our LayerCert framework considers the nested hyperplane arrangement structure induced by the layers of the ReLU network and explores regions in a hierarchical manner. We show that, under certain conditions on the algorithm parameters, LayerCert provably reduces the number and size of the convex programs that one needs to solve compared to GeoCert. Furthermore, our LayerCert framework allows the incorporation of lower bounding routines based on convex relaxations to further improve performance. Experimental results demonstrate that LayerCert can significantly reduce both the number of convex programs solved and the running time over the state-of-the-art.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 57cd2d71-724b-4e18-b08c-dbe9baa3df72Cited by top-tier papers2
- Fast Geometric Projections for Local Robustness CertificationAymeric Fromherz, Klas Leino, Matt Fredrikson, Bryan Parno et al.ICLR 2021 · 34 citations
- SmoothHess: ReLU Network Feature Interactions via Stein's LemmaMax Torop, Aria Masoomi, Davin Hill, Kivanç Köse et al.NeurIPS 2023 · 9 citations
Builds on2
Related papers
- On the Tightness of Semidefinite Relaxations for Certifying Robustness to Adversarial ExamplesRichard Y. ZhangNeurIPS 2020 · 30 citations
- The Convex Relaxation Barrier, Revisited: Tightened Single-Neuron Relaxations for Neural Network VerificationChristian Tjandraatmadja, Ross Anderson, Joey Huchette, Will Ma et al.NeurIPS 2020 · 102 citations
- Tightening Robustness Verification of Convolutional Neural Networks with Fine-Grained Linear ApproximationYiting Wu, Min ZhangAAAI 2021 · 23 citations
- Tighter Truncated Rectangular Prism Approximation for RNN Robustness VerificationXingqi Lin, Liangyu Chen, Min Wu, Min Zhang et al.AAAI 2026
- Tight Neural Network Verification via Semidefinite Relaxations and Linear ReformulationsJianglin Lan, Yang Zheng, Alessio LomuscioAAAI 2022 · 22 citations
