BNN-DP: Robustness Certification of Bayesian Neural Networks via Dynamic Programming
Steven Adams, Andrea Patane, Morteza Lahijanian, Luca Laurenti
Abstract
In this paper, we introduce BNN-DP, an efficient algorithmic framework for analysis of adversarial robustness of Bayesian Neural Networks (BNNs). Given a compact set of input points , BNN-DP computes lower and upper bounds on the BNN's predictions for all the points in . The framework is based on an interpretation of BNNs as stochastic dynamical systems, which enables the use of Dynamic Programming (DP) algorithms to bound the prediction range along the layers of the network. Specifically, the method uses bound propagation techniques and convex relaxations to derive a backward recursion procedure to over-approximate the prediction range of the BNN with piecewise affine functions. The algorithm is general and can handle both regression and classification tasks. On a set of experiments on various regression and classification tasks and BNN architectures, we show that BNN-DP outperforms state-of-the-art methods by up to four orders of magnitude in both tightness of the bounds and computational efficiency.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f674fc40-ceeb-49da-9c17-0cd563f81dfdCited by top-tier papers1
Ask how each one uses itBuilds on3
- Robustness of Bayesian Neural Networks to Gradient-Based AttacksGinevra Carbone, Matthew Wicker, Luca Laurenti, Andrea Patané et al.NeurIPS 2020 · 85 citations
- Make Sure You're Unsure: A Framework for Verifying Probabilistic SpecificationsLeonard Berrada, Sumanth Dathathri, Krishnamurthy Dvijotham, Robert Stanforth et al.NeurIPS 2021 · 22 citations
- Infinite Time Horizon Safety of Bayesian Neural NetworksMathias Lechner, Dorde Zikelic, Krishnendu Chatterjee, Thomas A. HenzingerNeurIPS 2021 · 20 citations
Related papers
- Robust Bayesian Neural Networks by Spectral Expectation Bound RegularizationJiaru Zhang, Yang Hua, Zhengui Xue, Tao Song et al.CVPR 2021
- Probabilistic Robustness Certificates against Adversarial AttacksSara Taheri, Majid ZamaniICML 2026
- Scalable Verified Training for Provably Robust Image ClassificationSven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel et al.ICCV 2019 · 196 citations
- Quantifying Point-Prediction Uncertainty in Neural Networks via Residual Estimation with an I/O KernelXin Qiu, Elliot Meyerson, Risto MiikkulainenICLR 2020 · 60 citations
- Improving Bayesian Neural Networks by Adversarial SamplingJiaru Zhang, Yang Hua, Tao Song, Hao Wang et al.AAAI 2022 · 14 citations
