Precise and Generalized Robustness Certification for Neural Networks

06/11/2023
by   Yuanyuan Yuan, et al.
0

The objective of neural network (NN) robustness certification is to determine if a NN changes its predictions when mutations are made to its inputs. While most certification research studies pixel-level or a few geometrical-level and blurring operations over images, this paper proposes a novel framework, GCERT, which certifies NN robustness under a precise and unified form of diverse semantic-level image mutations. We formulate a comprehensive set of semantic-level image mutations uniformly as certain directions in the latent space of generative models. We identify two key properties, independence and continuity, that convert the latent space into a precise and analysis-friendly input space representation for certification. GCERT can be smoothly integrated with de facto complete, incomplete, or quantitative certification frameworks. With its precise input space representation, GCERT enables for the first time complete NN robustness certification with moderate cost under diverse semantic-level input mutations, such as weather-filter, style transfer, and perceptual changes (e.g., opening/closing eyes). We show that GCERT enables certifying NN robustness under various common and security-sensitive scenarios like autonomous driving.

READ FULL TEXT

page 4

page 5

page 12

research
04/05/2019

Image2StyleGAN: How to Embed Images Into the StyleGAN Latent Space?

We propose an efficient algorithm to embed a given image into the latent...
research
12/19/2019

Towards Verifying Robustness of Neural Networks Against Semantic Perturbations

Verifying robustness of neural networks given a specified threat model i...
research
10/20/2022

Diffusion Models already have a Semantic Latent Space

Diffusion models achieve outstanding generative performance in various d...
research
04/30/2020

Robustness Certification of Generative Models

Generative neural networks can be used to specify continuous transformat...
research
09/29/2022

Model Zoos: A Dataset of Diverse Populations of Neural Network Models

In the last years, neural networks (NN) have evolved from laboratory env...
research
06/23/2022

Measuring Representational Robustness of Neural Networks Through Shared Invariances

A major challenge in studying robustness in deep learning is defining th...
research
09/12/2023

Neural Network Layer Matrix Decomposition reveals Latent Manifold Encoding and Memory Capacity

We prove the converse of the universal approximation theorem, i.e. a neu...

Please sign up or login with your details

Forgot password? Click here to reset