Neural Network Control Policy Verification With Persistent Adversarial Perturbation
Yuh-Shyang Wang, Lily Weng, Luca Daniel
Abstract
Deep neural networks are known to be fragile to small adversarial perturbations, which raises serious concerns when a neural network policy is interconnected with a physical system in a closed loop. In this paper, we show how to combine recent works on static neural network certification tools with robust control theory to certify a neural network policy in a control loop. We give a sufficient condition and an algorithm to ensure that the closed loop state and control constraints are satisfied when the persistent adversarial perturbation is ∞ norm bounded. Our method is based on finding a positively invariant set of the closed loop dynamical system, and thus we do not require the continuity of the neural network policy. Along with the verification result, we also develop an effective attack strategy for neural network control systems that outperforms exhaustive Monte-Carlo search significantly. We show that our certification algorithm works well on learned models and could achieve 5 times better result than the traditional Lipschitz-based method to certify the robustness of a neural network policy on the cart-pole balance control problem.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dce4979d-4e88-4f2a-9790-d3242df64c79Builds on1
Related papers
- Towards Robust Neural Networks via Close-loop ControlZhuotong Chen, Qianxiao Li, Zheng ZhangICLR 2021 · 5 citations
- An Iterative Scheme of Safe Reinforcement Learning for Nonlinear Systems via Barrier Certificate GenerationZhengfeng Yang, Yidan Zhang, Wang Lin, Xia Zeng et al.CAV 2021 · 15 citations
- Robustness Verification of Deep Reinforcement Learning Based Control Systems Using Reward MartingalesDapeng Zhi, Peixin Wang, Cheng Chen, Min ZhangAAAI 2024 · 4 citations
- Synthesizing Barrier Certificates of Neural Network Controlled Continuous Systems via ApproximationsMeng Sha, Xin Chen, Yuzhe Ji, Qingye Zhao et al.DAC 2021 · 14 citations
- Toward Evaluating Robustness of Deep Reinforcement Learning with Continuous ControlTsui-Wei Weng, Krishnamurthy (Dj) Dvijotham, Jonathan Uesato, Kai Xiao et al.ICLR 2020 · 34 citations
