Reducing DNN Properties to Enable Falsification with Adversarial Attacks
David Shriver, Sebastian G. Elbaum, Matthew B. Dwyer
Abstract
Deep Neural Networks (DNN) are increasingly being deployed in safety-critical domains, from autonomous vehicles to medical devices, where the consequences of errors demand techniques that can provide stronger guarantees about behavior than just high test accuracy. This paper explores broadening the application of existing adversarial attack techniques for the falsification of DNN safety properties. We contend and later show that such attacks provide a powerful repertoire of scalable algorithms for property falsification. To enable the broad application of falsification, we introduce a semantics-preserving reduction of multiple safety property types, which subsume prior work, into a set of equivalid correctness problems amenable to adversarial attacks. We evaluate our reduction approach as an enabler of falsification on a range of DNN correctness problems and show its cost-effectiveness and scalability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d0cae88f-bb76-4587-b904-ebd84766b91eCited by top-tier papers6
- ReMoS: Reducing Defect Inheritance in Transfer Learning via Relevant Model SlicingZiqi Zhang, Yuanchun Li, Jindong Wang, Bingyan Liu et al.ICSE 2022 · 28 citations
- Neural termination analysisMirco Giacobbe, Daniel Kroening, Julian ParsertFSE 2022 · 16 citations
- Harnessing Neuron Stability to Improve DNN VerificationHai Duong, Dong Xu, ThanhVu Nguyen, Matthew B. DwyerFSE 2024 · 13 citations
- Toward Improving the Robustness of Deep Learning Models via Model TransformationYingyi Zhang, Zan Wang, Jiajun Jiang, Hanmo You et al.ASE 2022 · 7 citations
- Distribution Models for Falsification and Verification of DNNsFelipe Toledo, David Shriver, Sebastian G. Elbaum, Matthew B. DwyerASE 2021 · 4 citations
Builds on9
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov et al.S&P 2018 · 987 citations
- Formal Security Analysis of Neural Networks using Symbolic IntervalsShiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang et al.USENIX Security 2018 · 523 citations
- Efficient Verification of ReLU-Based Neural Networks via Dependency AnalysisElena Botoeva, Panagiotis Kouvaros, Jan Kronqvist, Alessio Lomuscio et al.AAAI 2020 · 140 citations
- Verification of Deep Convolutional Neural Networks Using ImageStarsHoang-Dung Tran, Stanley Bak, Weiming Xiang, Taylor T. JohnsonCAV 2020 · 122 citations
Related papers
- DeepDyve: Dynamic Verification for Deep Neural NetworksYu Li, Min Li, Bo Luo, Ye Tian et al.CCS 2020 · 28 citations
- LiRTest: augmenting LiDAR point clouds for automated testing of autonomous driving systemsAn Guo, Yang Feng, Zhenyu ChenISSTA 2022 · 30 citations
- Patch Synthesis for Property Repair of Deep Neural NetworksZhiming Chi, Jianan Ma, Pengfei Yang, Cheng-Chao Huang et al.ICSE 2025 · 2 citations
- VNN: Verification-Friendly Neural Networks with Hard Robustness GuaranteesAnahita Baninajjar, Ahmed Rezine, Amir AminifarICML 2024 · 2 citations
- Evaluating Deep Neural Networks in Deployment: A Comparative Study (Replicability Study)Eduard Pinconschi, Divya Gopinath, Rui Abreu, Corina S. PasareanuISSTA 2024
