BNN-DP: Robustness Certification of Bayesian Neural Networks via Dynamic Programming
Steven Adams, Andrea Patane, Morteza Lahijanian, Luca Laurenti
摘要
In this paper, we introduce BNN-DP, an efficient algorithmic framework for analysis of adversarial robustness of Bayesian Neural Networks (BNNs). Given a compact set of input points , BNN-DP computes lower and upper bounds on the BNN's predictions for all the points in . The framework is based on an interpretation of BNNs as stochastic dynamical systems, which enables the use of Dynamic Programming (DP) algorithms to bound the prediction range along the layers of the network. Specifically, the method uses bound propagation techniques and convex relaxations to derive a backward recursion procedure to over-approximate the prediction range of the BNN with piecewise affine functions. The algorithm is general and can handle both regression and classification tasks. On a set of experiments on various regression and classification tasks and BNN architectures, we show that BNN-DP outperforms state-of-the-art methods by up to four orders of magnitude in both tightness of the bounds and computational efficiency.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper3
- Robustness of Bayesian Neural Networks to Gradient-Based AttacksGinevra Carbone, Matthew Wicker, Luca Laurenti, Andrea Patané 等NeurIPS 2020 · 被引用 85 次
- Make Sure You're Unsure: A Framework for Verifying Probabilistic SpecificationsLeonard Berrada, Sumanth Dathathri, Krishnamurthy Dvijotham, Robert Stanforth 等NeurIPS 2021 · 被引用 22 次
- Infinite Time Horizon Safety of Bayesian Neural NetworksMathias Lechner, Dorde Zikelic, Krishnendu Chatterjee, Thomas A. HenzingerNeurIPS 2021 · 被引用 20 次
相关 Paper
- Robust Bayesian Neural Networks by Spectral Expectation Bound RegularizationJiaru Zhang, Yang Hua, Zhengui Xue, Tao Song 等CVPR 2021
- Probabilistic Robustness Certificates against Adversarial AttacksSara Taheri, Majid ZamaniICML 2026
- Scalable Verified Training for Provably Robust Image ClassificationSven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel 等ICCV 2019 · 被引用 196 次
- Quantifying Point-Prediction Uncertainty in Neural Networks via Residual Estimation with an I/O KernelXin Qiu, Elliot Meyerson, Risto MiikkulainenICLR 2020 · 被引用 60 次
- Improving Bayesian Neural Networks by Adversarial SamplingJiaru Zhang, Yang Hua, Tao Song, Hao Wang 等AAAI 2022 · 被引用 14 次
