Enumerating Safe Regions in Deep Neural Networks with Provable Probabilistic Guarantees

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Marzari, Luca, Corsi, Davide, Marchesini, Enrico, Farinelli, Alessandro, Cicalese, Ferdinando
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866929248985415680
author Marzari, Luca
Corsi, Davide
Marchesini, Enrico
Farinelli, Alessandro
Cicalese, Ferdinando
author_facet Marzari, Luca
Corsi, Davide
Marchesini, Enrico
Farinelli, Alessandro
Cicalese, Ferdinando
contents Identifying safe areas is a key point to guarantee trust for systems that are based on Deep Neural Networks (DNNs). To this end, we introduce the AllDNN-Verification problem: given a safety property and a DNN, enumerate the set of all the regions of the property input domain which are safe, i.e., where the property does hold. Due to the #P-hardness of the problem, we propose an efficient approximation method called epsilon-ProVe. Our approach exploits a controllable underestimation of the output reachable sets obtained via statistical prediction of tolerance limits, and can provide a tight (with provable probabilistic guarantees) lower estimate of the safe areas. Our empirical evaluation on different standard benchmarks shows the scalability and effectiveness of our method, offering valuable insights for this new type of verification of DNNs.
format Preprint
id arxiv_https___arxiv_org_abs_2308_09842
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Enumerating Safe Regions in Deep Neural Networks with Provable Probabilistic Guarantees
Marzari, Luca
Corsi, Davide
Marchesini, Enrico
Farinelli, Alessandro
Cicalese, Ferdinando
Machine Learning
Artificial Intelligence
Identifying safe areas is a key point to guarantee trust for systems that are based on Deep Neural Networks (DNNs). To this end, we introduce the AllDNN-Verification problem: given a safety property and a DNN, enumerate the set of all the regions of the property input domain which are safe, i.e., where the property does hold. Due to the #P-hardness of the problem, we propose an efficient approximation method called epsilon-ProVe. Our approach exploits a controllable underestimation of the output reachable sets obtained via statistical prediction of tolerance limits, and can provide a tight (with provable probabilistic guarantees) lower estimate of the safe areas. Our empirical evaluation on different standard benchmarks shows the scalability and effectiveness of our method, offering valuable insights for this new type of verification of DNNs.
title Enumerating Safe Regions in Deep Neural Networks with Provable Probabilistic Guarantees
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2308.09842