VNN: Verification-Friendly Neural Networks with Hard Robustness Guarantees

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Baninajjar, Anahita, Rezine, Ahmed, Aminifar, Amir
Format: Preprint
Veröffentlicht: 2023
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866913383154974720
author Baninajjar, Anahita
Rezine, Ahmed
Aminifar, Amir
author_facet Baninajjar, Anahita
Rezine, Ahmed
Aminifar, Amir
contents Machine learning techniques often lack formal correctness guarantees, evidenced by the widespread adversarial examples that plague most deep-learning applications. This lack of formal guarantees resulted in several research efforts that aim at verifying Deep Neural Networks (DNNs), with a particular focus on safety-critical applications. However, formal verification techniques still face major scalability and precision challenges. The over-approximation introduced during the formal verification process to tackle the scalability challenge often results in inconclusive analysis. To address this challenge, we propose a novel framework to generate Verification-Friendly Neural Networks (VNNs). We present a post-training optimization framework to achieve a balance between preserving prediction performance and verification-friendliness. Our proposed framework results in VNNs that are comparable to the original DNNs in terms of prediction performance, while amenable to formal verification techniques. This essentially enables us to establish robustness for more VNNs than their DNN counterparts, in a time-efficient manner.
format Preprint
id arxiv_https___arxiv_org_abs_2312_09748
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle VNN: Verification-Friendly Neural Networks with Hard Robustness Guarantees
Baninajjar, Anahita
Rezine, Ahmed
Aminifar, Amir
Machine Learning
Software Engineering
Machine learning techniques often lack formal correctness guarantees, evidenced by the widespread adversarial examples that plague most deep-learning applications. This lack of formal guarantees resulted in several research efforts that aim at verifying Deep Neural Networks (DNNs), with a particular focus on safety-critical applications. However, formal verification techniques still face major scalability and precision challenges. The over-approximation introduced during the formal verification process to tackle the scalability challenge often results in inconclusive analysis. To address this challenge, we propose a novel framework to generate Verification-Friendly Neural Networks (VNNs). We present a post-training optimization framework to achieve a balance between preserving prediction performance and verification-friendliness. Our proposed framework results in VNNs that are comparable to the original DNNs in terms of prediction performance, while amenable to formal verification techniques. This essentially enables us to establish robustness for more VNNs than their DNN counterparts, in a time-efficient manner.
title VNN: Verification-Friendly Neural Networks with Hard Robustness Guarantees
topic Machine Learning
Software Engineering
url https://arxiv.org/abs/2312.09748