Robustness Guarantees for Deep Neural Networks on Videos
Min Wu, Marta Kwiatkowska
摘要
The widespread adoption of deep learning models places demands on their robustness. In this paper, we consider the robustness of deep neural networks on videos, which comprise both the spatial features of individual frames extracted by a convolutional neural network and the temporal dynamics between adjacent frames captured by a recurrent neural network. To measure robustness, we study the maximum safe radius problem, which computes the minimum distance from the optical flow sequence obtained from a given input to that of an adversarial example in the neighbourhood of the input. We demonstrate that, under the assumption of Lipschitz continuity, the problem can be approximated using finite optimisation via discretising the optical flow space, and the approximation has provable guarantees. We then show that the finite optimisation problem can be solved by utilising a two-player turn-based game in a cooperative setting, where the first player selects the optical flows and the second player determines the dimensions to be manipulated in the chosen flow. We employ an anytime approach to solve the game, in the sense of approximating the value of the game by monotonically improving its upper and lower bounds. We exploit a gradient-based search algorithm to compute the upper bounds, and the admissible A* algorithm to update the lower bounds. Finally, we evaluate our framework on the UCF101 video dataset.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- VeriX: Towards Verified Explainability of Deep Neural NetworksMin Wu, Haoze Wu, Clark W. BarrettNeurIPS 2023 · 被引用 39 次
- Scalable Polyhedral Verification of Recurrent Neural NetworksWonryong Ryou, Jiayu Chen, Mislav Balunovic, Gagandeep Singh 等CAV 2021 · 被引用 32 次
- Efficient Certification of Spatial RobustnessAnian Ruoss, Maximilian Baader, Mislav Balunovic, Martin T. VechevAAAI 2021 · 被引用 26 次
- A Tale of Two Approximations: Tightening Over-Approximation for DNN Robustness Verification via Under-ApproximationZhiyi Xue, Si Liu, Zhaodi Zhang, Yiting Wu 等ISSTA 2023 · 被引用 5 次
- Scalable Neural Network Geometric Robustness Validation via Hölder OptimisationYanghao Zhang, Panagiotis Kouvaros, Alessio LomuscioNeurIPS 2025 · 被引用 4 次
它引用的顶会 Paper2
相关 Paper
- AdvIT: Adversarial Frames Identifier Based on Temporal Consistency in VideosChaowei Xiao, Ruizhi Deng, Bo Li, Taesung Lee 等ICCV 2019 · 被引用 64 次
- Merry Go Round: Rotate a Frame and Fool a DNNDaksh Thapar, Aditya Nigam, Chetan AroraCVPR 2022 · 被引用 1 次
- Attacking Optical FlowAnurag Ranjan, Joel Janai, Andreas Geiger, Michael J. BlackICCV 2019 · 被引用 93 次
- Certified Robustness via Dynamic Margin Maximization and Improved Lipschitz RegularizationMahyar Fazlyab, Taha Entesari, Aniket Roy, Rama ChellappaNeurIPS 2023 · 被引用 26 次
- Exploring perceptual straightness in learned visual representationsAnne Harrington, Vasha DuTell, Ayush Tewari, Mark Hamilton 等ICLR 2023
