Maximum Resilience of Artificial Neural Networks

被引:158
作者
Cheng, Chih-Hong [1 ]
Nuehrenberg, Georg [1 ]
Ruess, Harald [1 ]
机构
[1] Fortiss, Guerickestr 25, D-80805 Munich, Germany
来源
AUTOMATED TECHNOLOGY FOR VERIFICATION AND ANALYSIS (ATVA 2017) | 2017年 / 10482卷
关键词
INTEGER;
D O I
10.1007/978-3-319-68167-2_18
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The deployment of Artificial Neural Networks (ANNs) in safety-critical applications poses a number of new verification and certification challenges. In particular, for ANN-enabled self-driving vehicles it is important to establish properties about the resilience of ANNs to noisy or even maliciously manipulated sensory input. We are addressing these challenges by defining resilience properties of ANN-based classifiers as the maximum amount of input or sensor perturbation which is still tolerated. This problem of computing maximum perturbation bounds for ANNs is then reduced to solving mixed integer optimization problems (MIP). A number of MIP encoding heuristics are developed for drastically reducing MIP-solver runtimes, and using parallelization of MIP-solvers results in an almost linear speed-up in the number (up to a certain limit) of computing cores in our experiments. We demonstrate the effectiveness and scalability of our approach by means of computing maximum resilience bounds for a number of ANN benchmark sets ranging from typical image recognition scenarios to the autonomous maneuvering of robots.
引用
收藏
页码:251 / 268
页数:18
相关论文
共 23 条
  • [1] Abu-Mostafa Y.S., 2012, LEARNING DATA, V4
  • [2] Amodei D., 2016, ARXIV160606565
  • [3] Nguyen A, 2015, PROC CVPR IEEE, P427, DOI 10.1109/CVPR.2015.7298640
  • [4] [Anonymous], 2013, Playing atari with deep reinforcement learning
  • [5] Bastani O, 2016, P 30 C NEUR INF PROC
  • [6] Bhattacharyya S, 2015, INT CONF UNMAN AIRCR, P270, DOI 10.1109/ICUAS.2015.7152300
  • [7] BjOrner N., 2015, P 21 INT C TOOLS ALG, P194, DOI [DOI 10.1007/978-3-662-46681-0, 10.1007/978-3-662-46681-0_14, DOI 10.1007/978-3-662-46681-0_14]
  • [8] Cousot P, 1977, POPL, P238, DOI [DOI 10.1145/512950.512973, 10.1145/512950.512973]
  • [9] Goodfellow Ian J, 2014, CoRR abs/1412.6572
  • [10] Review of Nonlinear Mixed-Integer and Disjunctive Programming Techniques
    Grossmann, Ignacio E.
    [J]. OPTIMIZATION AND ENGINEERING, 2002, 3 (03) : 227 - 252