A domain-theoretic framework for robustness analysis of neural networks

被引:1
作者
Zhou, Can [1 ]
Shaikh, Razin A. [1 ,2 ]
Li, Yiran [3 ]
Farjudian, Amin [3 ]
机构
[1] Univ Oxford, Dept Comp Sci, Oxford, England
[2] Quantinuum Ltd, Oxford, England
[3] Univ Nottingham Ningbo China, Sch Comp Sci, Ningbo, Peoples R China
基金
中国国家自然科学基金;
关键词
Domain theory; neural network; robustness; Lipschitz constant; Clarke-gradient; QUERY-DRIVEN COMMUNICATION; REAL; SEMANTICS; COMPUTABILITY; COMPUTATION; SPACES;
D O I
10.1017/S0960129523000142
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A domain-theoretic framework is presented for validated robustness analysis of neural networks. First, global robustness of a general class of networks is analyzed. Then, using the fact that Edalat's domain-theoretic L-derivative coincides with Clarke's generalized gradient, the framework is extended for attack-agnostic local robustness analysis. The proposed framework is ideal for designing algorithms which are correct by construction. This claim is exemplified by developing a validated algorithm for estimation of Lipschitz constant of feedforward regressors. The completeness of the algorithm is proved over differentiable networks and also over general position ReLU networks. Computability results are obtained within the framework of effectively given domains. Using the proposed domain model, differentiable and non-differentiable networks can be analyzed uniformly. The validated algorithm is implemented using arbitrary-precision interval arithmetic, and the results of some experiments are presented. The software implementation is truly validated, as it handles floating-point errors as well.
引用
收藏
页码:68 / 105
页数:38
相关论文
共 90 条
[11]  
Chen Tianlong, 2020, Advances in Neural Information Processing Systems, V33
[12]  
Clarke F.H., 1990, OPTIMIZATION NONSMOO
[13]  
Clarke FH., 1998, NONSMOOTH ANAL CONTR
[14]  
Cousot Patrick, 1977, P 4 ACM SIGACT SIGPL, P238, DOI [10.1145/512950.512973, DOI 10.1145/512950.512973]
[15]  
Di Gianantonio P, 2013, LECT NOTES COMPUT SC, V7794, P337, DOI 10.1007/978-3-642-37075-5_22
[16]   Steps Toward Robust Artificial Intelligence [J].
Dietterich, Thomas G. .
AI MAGAZINE, 2017, 38 (03) :3-24
[17]   Real number computability and domain theory [J].
DiGianantonio, P .
INFORMATION AND COMPUTATION, 1996, 127 (01) :11-25
[18]   Artificial Intelligence Aided Automated Design for Reliability of Power Electronic Systems [J].
Dragicevic, Tomislav ;
Wheeler, Patrick ;
Blaabjerg, Frede .
IEEE TRANSACTIONS ON POWER ELECTRONICS, 2019, 34 (08) :7161-7171
[19]   DYNAMICAL-SYSTEMS, MEASURES, AND FRACTALS VIA DOMAIN THEORY [J].
EDALAT, A .
INFORMATION AND COMPUTATION, 1995, 120 (01) :32-48
[20]  
Edalat A, 2005, IEEE S LOG, P417