Tight Verification of Probabilistic Robustness in Bayesian Neural Networks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Batten, Ben, Hosseini, Mehran, Lomuscio, Alessio
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913247511183360
author Batten, Ben
Hosseini, Mehran
Lomuscio, Alessio
author_facet Batten, Ben
Hosseini, Mehran
Lomuscio, Alessio
contents We introduce two algorithms for computing tight guarantees on the probabilistic robustness of Bayesian Neural Networks (BNNs). Computing robustness guarantees for BNNs is a significantly more challenging task than verifying the robustness of standard Neural Networks (NNs) because it requires searching the parameters' space for safe weights. Moreover, tight and complete approaches for the verification of standard NNs, such as those based on Mixed-Integer Linear Programming (MILP), cannot be directly used for the verification of BNNs because of the polynomial terms resulting from the consecutive multiplication of variables encoding the weights. Our algorithms efficiently and effectively search the parameters' space for safe weights by using iterative expansion and the network's gradient and can be used with any verification algorithm of choice for BNNs. In addition to proving that our algorithms compute tighter bounds than the SoA, we also evaluate our algorithms against the SoA on standard benchmarks, such as MNIST and CIFAR10, showing that our algorithms compute bounds up to 40% tighter than the SoA.
format Preprint
id arxiv_https___arxiv_org_abs_2401_11627
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Tight Verification of Probabilistic Robustness in Bayesian Neural Networks
Batten, Ben
Hosseini, Mehran
Lomuscio, Alessio
Machine Learning
Artificial Intelligence
Formal Languages and Automata Theory
Logic in Computer Science
68T27 (Primary) 68T45, 68T07, 68T01 (Secondary)
I.2.0; I.2.4; F.3.1; D.2.4
We introduce two algorithms for computing tight guarantees on the probabilistic robustness of Bayesian Neural Networks (BNNs). Computing robustness guarantees for BNNs is a significantly more challenging task than verifying the robustness of standard Neural Networks (NNs) because it requires searching the parameters' space for safe weights. Moreover, tight and complete approaches for the verification of standard NNs, such as those based on Mixed-Integer Linear Programming (MILP), cannot be directly used for the verification of BNNs because of the polynomial terms resulting from the consecutive multiplication of variables encoding the weights. Our algorithms efficiently and effectively search the parameters' space for safe weights by using iterative expansion and the network's gradient and can be used with any verification algorithm of choice for BNNs. In addition to proving that our algorithms compute tighter bounds than the SoA, we also evaluate our algorithms against the SoA on standard benchmarks, such as MNIST and CIFAR10, showing that our algorithms compute bounds up to 40% tighter than the SoA.
title Tight Verification of Probabilistic Robustness in Bayesian Neural Networks
topic Machine Learning
Artificial Intelligence
Formal Languages and Automata Theory
Logic in Computer Science
68T27 (Primary) 68T45, 68T07, 68T01 (Secondary)
I.2.0; I.2.4; F.3.1; D.2.4
url https://arxiv.org/abs/2401.11627