Relational DNN Verification With Cross Executional Bound Refinement
Abstract: We focus on verifying relational properties defined over deep neural networks (DNNs) such as robustness against universal adversarial perturbations (UAP), certified worst-case hamming distance for binary string classifications, etc. Precise verification of these properties requires reasoning about multiple executions of the same DNN. However, most of the existing works in DNN verification only handle properties defined over single executions and as a result, are imprecise for relational properties. Though few recent works for relational DNN verification, capture linear dependencies between the inputs of multiple executions, they do not leverage dependencies between the outputs of hidden layers producing imprecise results. We develop a scalable relational verifier RACoon that utilizes cross-execution dependencies at all layers of the DNN gaining substantial precision over SOTA baselines on a wide range of datasets, networks, and relational properties.
- Artificial neural networks in medical diagnosis. Journal of Applied Biomedicine, 11(2), 2013.
- Strong mixed-integer programming formulations for trained neural networks. Mathematical Programming, 2020.
- Improved geometric path enumeration for verifying relu neural networks. In Lahiri, S. K. and Wang, C. (eds.), Computer Aided Verification - 32nd International Conference, CAV 2020, Los Angeles, CA, USA, July 21-24, 2020, Proceedings, Part I, volume 12224 of Lecture Notes in Computer Science, pp. 66–96. Springer, 2020. doi: 10.1007/978-3-030-53288-8“˙4. URL https://doi.org/10.1007/978-3-030-53288-8_4.
- Adversarial training and provable defenses: Bridging the gap. In International Conference on Learning Representations, 2020. URL https://openreview.net/forum?id=SJxSDxrKDr.
- End to end learning for self-driving cars. arXiv preprint arXiv:1604.07316, 2016.
- Convex optimization. Cambridge university press, 2004.
- First three years of the international verification of neural networks competition (vnn-comp). International Journal on Software Tools for Technology Transfer, pp. 1–11, 2023.
- Branch and bound for piecewise linear neural network verification. Journal of Machine Learning Research, 21(2020), 2020a.
- An efficient nonconvex reformulation of stagewise convex optimization problems. Advances in Neural Information Processing Systems, 33, 2020b.
- Certified adversarial robustness via randomized smoothing. In Chaudhuri, K. and Salakhutdinov, R. (eds.), Proceedings of the 36th International Conference on Machine Learning, volume 97 of Proceedings of Machine Learning Research, pp. 1310–1320. PMLR, 09–15 Jun 2019. URL https://proceedings.mlr.press/v97/cohen19c.html.
- Ehlers, R. Formal verification of piece-wise linear feed-forward neural networks. In International Symposium on Automated Technology for Verification and Analysis, 2017.
- Complete verification via multi-neuron relaxation guided branch-and-bound. In International Conference on Learning Representations, 2022. URL https://openreview.net/forum?id=l_amHf1oaK.
- Fast geometric projections for local robustness certification. In International Conference on Learning Representations, 2021. URL https://openreview.net/forum?id=zWy1uxjDdZJ.
- Ai2: Safety and robustness certification of neural networks with abstract interpretation. In 2018 IEEE Symposium on Security and Privacy (SP), 2018.
- Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572, 2014.
- Gurobi Optimization, LLC. Gurobi optimizer reference manual, 2018.
- Hamming, R. W. Error detecting and error correcting codes. The Bell system technical journal, 29(2):147–160, 1950.
- Certifair: A framework for certified global fairness of neural networks. Proceedings of the AAAI Conference on Artificial Intelligence, 37(7):8237–8245, Jun. 2023.
- Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980, 2014.
- Adversarial music: Real world audio adversary against wake-word detection system. In Proc. Neural Information Processing Systems (NeurIPS), pp. 11908–11918, 2019a.
- Adversarial camera stickers: A physical camera-based attack on deep learning systems. In Proc. International Conference on Machine Learning, ICML, volume 97, pp. 3896–3904, 2019b.
- Double sampling randomized smoothing. In Chaudhuri, K., Jegelka, S., Song, L., Szepesvari, C., Niu, G., and Sabato, S. (eds.), Proceedings of the 39th International Conference on Machine Learning, volume 162 of Proceedings of Machine Learning Research, pp. 13163–13208. PMLR, 17–23 Jul 2022. URL https://proceedings.mlr.press/v162/li22aa.html.
- Exploring practical vulnerabilities of machine learning-based wireless systems. In 20th USENIX Symposium on Networked Systems Design and Implementation, NSDI 2023, Boston, MA, April 17-19, 2023, pp. 1801–1817. USENIX Association, 2023.
- Towards deep learning models resistant to adversarial attacks. In International Conference on Learning Representations, 2018. URL https://openreview.net/forum?id=rJzIBfZAb.
- Differentiable abstract interpretation for provably robust neural networks. In Dy, J. and Krause, A. (eds.), Proceedings of the 35th International Conference on Machine Learning, volume 80 of Proceedings of Machine Learning Research, pp. 3578–3586. PMLR, 10–15 Jul 2018. URL https://proceedings.mlr.press/v80/mirman18b.html.
- Universal adversarial perturbations. In Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 1765–1773, 2017.
- Scaling the convex barrier with active sets. In 9th International Conference on Learning Representations, ICLR 2021, Virtual Event, Austria, May 3-7, 2021, 2021.
- Deepcert: Verification of contextually relevant robustness for neural network image classifiers. In Habli, I., Sujan, M., and Bitsch, F. (eds.), Computer Safety, Reliability, and Security, pp. 3–17, Cham, 2021. Springer International Publishing. ISBN 978-3-030-83903-1.
- Reludiff: Differential verification of deep neural networks. In Proceedings of the ACM/IEEE 42nd International Conference on Software Engineering, ICSE ’20, pp. 714–726, New York, NY, USA, 2020. Association for Computing Machinery. ISBN 9781450371216. doi: 10.1145/3377811.3380337. URL https://doi.org/10.1145/3377811.3380337.
- Neurodiff: Scalable differential verification of neural networks using fine-grained approximation. In Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering, ASE ’20, pp. 784–796, New York, NY, USA, 2021. Association for Computing Machinery. ISBN 9781450367684. doi: 10.1145/3324884.3416560. URL https://doi.org/10.1145/3324884.3416560.
- An empirical investigation of randomized defenses against adversarial attacks. arXiv preprint arXiv:1909.05580, 2019.
- Verification of non-linear specifications for neural networks. In International Conference on Learning Representations, 2019. URL https://openreview.net/forum?id=HyeFAsRctQ.
- A convex relaxation barrier to tight robustness verification of neural networks. In Wallach, H., Larochelle, H., Beygelzimer, A., d'Alché-Buc, F., Fox, E., and Garnett, R. (eds.), Advances in Neural Information Processing Systems, volume 32. Curran Associates, Inc., 2019. URL https://proceedings.neurips.cc/paper_files/paper/2019/file/246a3c5544feb054f3ea718f61adfa16-Paper.pdf.
- Fast and effective robustness certification. Advances in Neural Information Processing Systems, 31, 2018.
- Beyond the single neuron convex barrier for neural network certification. In Advances in Neural Information Processing Systems, 2019a.
- An abstract domain for certifying neural networks. Proceedings of the ACM on Programming Languages, 3(POPL), 2019b.
- Abstract neural networks. In Static Analysis: 27th International Symposium, SAS 2020, Virtual Event, November 18–20, 2020, Proceedings 27, pp. 65–88. Springer, 2020.
- Efficient formal safety analysis of neural networks. In Advances in Neural Information Processing Systems, 2018.
- Beta-crown: Efficient bound propagation with per-neuron split constraints for complete and incomplete neural network verification. arXiv preprint arXiv:2103.06624, 2021.
- Provable defenses against adversarial examples via the convex outer adversarial polytope. In Dy, J. G. and Krause, A. (eds.), Proceedings of the 35th International Conference on Machine Learning, ICML 2018, Stockholmsmässan, Stockholm, Sweden, July 10-15, 2018, volume 80 of Proceedings of Machine Learning Research, pp. 5283–5292. PMLR, 2018. URL http://proceedings.mlr.press/v80/wong18a.html.
- Toward certified robustness against real-world distribution shifts. In 2023 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML), pp. 537–553. IEEE, 2023.
- Crfl: Certifiably robust federated learning against backdoor attacks. In International Conference on Machine Learning, pp. 11372–11382. PMLR, 2021.
- Automatic perturbation analysis for scalable certified robustness and beyond. In Proceedings of the 34th International Conference on Neural Information Processing Systems, NIPS’20, Red Hook, NY, USA, 2020. Curran Associates Inc. ISBN 9781713829546.
- Fast and complete: Enabling complete neural network verification with rapid and massively parallel incomplete verifiers. In International Conference on Learning Representations, 2021. URL https://openreview.net/forum?id=nVZtXBI6LNn.
- Towards robustness certification against universal perturbations. In The Eleventh International Conference on Learning Representations, 2023. URL https://openreview.net/forum?id=7GEvPKxjtt.
- Efficient neural network robustness certification with general activation functions. Advances in neural information processing systems, 31, 2018.
- Towards stable and efficient training of verifiably robust neural networks. In Proc. International Conference on Learning Representations (ICLR), 2020.
- General cutting planes for bound-propagation-based neural network verification. In Oh, A. H., Agarwal, A., Belgrave, D., and Cho, K. (eds.), Advances in Neural Information Processing Systems, 2022a. URL https://openreview.net/forum?id=5haAJAcofjc.
- Bagflip: A certified defense against data poisoning. In Oh, A. H., Agarwal, A., Belgrave, D., and Cho, K. (eds.), Advances in Neural Information Processing Systems, 2022b. URL https://openreview.net/forum?id=ZidkM5b92G.
Paper Prompts
Sign up for free to create and run prompts on this paper.