Shared Certificates for Neural Network Verification
Marc Fischer, Christian Sprecher, Dimitar I. Dimitrov, Gagandeep Singh, Martin T. Vechev
摘要
Abstract Existing neural network verifiers compute a proof that each input is handled correctly under a given perturbation by propagating a symbolic abstraction of reachable values at each layer. This process is repeated from scratch independently for each input (e.g., image) and perturbation (e.g., rotation), leading to an expensive overall proof effort when handling an entire dataset. In this work, we introduce a new method for reducing this verification cost without losing precision based on a key insight that abstractions obtained at intermediate layers for different inputs and perturbations can overlap or contain each other. Leveraging our insight, we introduce the general concept of shared certificates, enabling proof effort reuse across multiple inputs to reduce overall verification costs. We perform an extensive experimental evaluation to demonstrate the effectiveness of shared certificates in reducing the verification cost on a range of datasets and attack specifications on image classifiers including the popular patch and geometric perturbations. We release our implementation at https://github.com/eth-sri/proof-sharing .
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Incremental Verification of Neural NetworksShubham Ugare, Debangshu Banerjee, Sasa Misailovic, Gagandeep SinghPLDI 2023 · 被引用 19 次
- Incremental Randomized Smoothing CertificationShubham Ugare, Tarun Suresh, Debangshu Banerjee, Gagandeep Singh 等ICLR 2024 · 被引用 14 次
- Proof transfer for fast certification of multiple approximate neural networksShubham Ugare, Gagandeep Singh, Sasa MisailovicOOPSLA 2022 · 被引用 13 次
- Mini-Batch Robustness Verification of Deep Neural NetworksSaar Tzour-Shaday, Dana Drachsler-CohenOOPSLA 2025 · 被引用 1 次
它引用的顶会 Paper5
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov 等S&P 2018 · 被引用 987 次
- Certified Defenses for Adversarial PatchesPing-yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu 等ICLR 2020 · 被引用 194 次
- Certified Defense to Image Transformations via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevNeurIPS 2020 · 被引用 78 次
- ReluDiff: differential verification of deep neural networksBrandon Paulsen, Jingbo Wang, Chao WangICSE 2020 · 被引用 47 次
- NEURODIFF: Scalable Differential Verification of Neural Networks using Fine-Grained ApproximationBrandon Paulsen, Jingbo Wang, Jiawei Wang, Chao WangASE 2020 · 被引用 26 次
相关 Paper
- Towards Verifying Robustness of Neural Networks Against A Family of Semantic PerturbationsJeet Mohapatra, Tsui-Wei Weng, Pin-Yu Chen, Sijia Liu 等CVPR 2020
- Boosting Verified Training for Robust Image Classifications via AbstractionZhaodi Zhang, Zhiyi Xue, Yang Chen, Si Liu 等CVPR 2023
- Relational DNN Verification With Cross Executional Bound RefinementDebangshu Banerjee, Gagandeep SinghICML 2024 · 被引用 8 次
- Scalable Polyhedral Verification of Recurrent Neural NetworksWonryong Ryou, Jiayu Chen, Mislav Balunovic, Gagandeep Singh 等CAV 2021 · 被引用 32 次
- Towards Robustness Certification Against Universal PerturbationsYi Zeng, Zhouxing Shi, Ming Jin, Feiyang Kang 等ICLR 2023
