Verifying Properties of Binary Neural Networks Using Sparse Polynomial Optimization

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Yang, Jianting, Ðurašinović, Srećko, Lasserre, Jean-Bernard, Magron, Victor, Zhao, Jun
Formato: Preprint
Publicado: 2024
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866912327404617728
author Yang, Jianting
Ðurašinović, Srećko
Lasserre, Jean-Bernard
Magron, Victor
Zhao, Jun
author_facet Yang, Jianting
Ðurašinović, Srećko
Lasserre, Jean-Bernard
Magron, Victor
Zhao, Jun
contents This paper explores methods for verifying the properties of Binary Neural Networks (BNNs), focusing on robustness against adversarial attacks. Despite their lower computational and memory needs, BNNs, like their full-precision counterparts, are also sensitive to input perturbations. Established methods for solving this problem are predominantly based on Satisfiability Modulo Theories and Mixed-Integer Linear Programming techniques, which are characterized by NP complexity and often face scalability issues. We introduce an alternative approach using Semidefinite Programming relaxations derived from sparse Polynomial Optimization. Our approach, compatible with continuous input space, not only mitigates numerical issues associated with floating-point calculations but also enhances verification scalability through the strategic use of tighter first-order semidefinite relaxations. We demonstrate the effectiveness of our method in verifying robustness against both $\|.\|_\infty$ and $\|.\|_2$-based adversarial attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2405_17049
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Verifying Properties of Binary Neural Networks Using Sparse Polynomial Optimization
Yang, Jianting
Ðurašinović, Srećko
Lasserre, Jean-Bernard
Magron, Victor
Zhao, Jun
Machine Learning
Optimization and Control
This paper explores methods for verifying the properties of Binary Neural Networks (BNNs), focusing on robustness against adversarial attacks. Despite their lower computational and memory needs, BNNs, like their full-precision counterparts, are also sensitive to input perturbations. Established methods for solving this problem are predominantly based on Satisfiability Modulo Theories and Mixed-Integer Linear Programming techniques, which are characterized by NP complexity and often face scalability issues. We introduce an alternative approach using Semidefinite Programming relaxations derived from sparse Polynomial Optimization. Our approach, compatible with continuous input space, not only mitigates numerical issues associated with floating-point calculations but also enhances verification scalability through the strategic use of tighter first-order semidefinite relaxations. We demonstrate the effectiveness of our method in verifying robustness against both $\|.\|_\infty$ and $\|.\|_2$-based adversarial attacks.
title Verifying Properties of Binary Neural Networks Using Sparse Polynomial Optimization
topic Machine Learning
Optimization and Control
url https://arxiv.org/abs/2405.17049