University of Exeter
Browse

Global robustness evaluation of deep neural networks with provable guarantees for the hamming distance

Download (1.46 MB)
conference contribution
posted on 2025-08-01, 10:15 authored by W Ruan, M Wu, Y Sun, X Huang, D Kroening, M Kwiatkowska
Deployment of deep neural networks (DNNs) in safety-critical systems requires provable guarantees for their correct behaviours. We compute the maximal radius of a safe norm ball around a given input, within which there are no adversarial examples for a trained DNN. We define global robustness as an expectation of the maximal safe radius over a test dataset, and develop an algorithm to approximate the global robustness measure by iteratively computing its lower and upper bounds. Our algorithm is the first efficient method for the Hamming (L0) distance, and we hypothesise that this norm is a good proxy for a certain class of physical attacks. The algorithm is anytime, i.e., it returns intermediate bounds and robustness estimates that are gradually, but strictly, improved as the computation proceeds; tensor-based, i.e., the computation is conducted over a set of inputs simultaneously to enable efficient GPU computation; and has provable guarantees, i.e., both the bounds and the robustness estimates can converge to their optimal values. Finally, we demonstrate the utility of our approach by applying the algorithm to a set of challenging problems.

Funding

EP/M019918/1

Engineering and Physical Sciences Research Council (EPSRC)

History

Related Materials

  1. 1.
    ISBN - Is published in urn:isbn:9781000000000
  2. 2.

Rights

© 2019 International Joint Conferences on Artificial Intelligence. All right reserved.

Notes

This is the final version. Available from IJCAI via the DOI in this record

Publisher

IJCAI

Version

  • Version of Record

Language

en

FCD date

2020-08-04T09:58:04Z

FOA date

2020-08-04T10:01:41Z

Citation

Proceedings of the 28th International Joint Conference on Artificial Intelligence (IJCAI 2019), 10-16 August 2019, Macau, China, pp. 5944-5952.

Department

  • Computer Science

Usage metrics

    University of Exeter

    Categories

    No categories selected

    Keywords

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC