Towards Stable and Efficient Training of Verifiably Robust Neural Networks

06/14/2019
by   Huan Zhang, et al.
0

Training neural networks with verifiable robustness guarantees is challenging. Several existing successful approaches utilize relatively tight linear relaxation based bounds of neural network outputs, but they can slow down training by a factor of hundreds and over-regularize the network. Meanwhile, interval bound propagation (IBP) based training is efficient and significantly outperform linear relaxation based methods on some tasks, yet it suffers from stability issues since the bounds are much looser. In this paper, we first interpret IBP training as training an augmented network which computes non-linear bounds, thus explaining its good performance. We then propose a new certified adversarial training method, CROWN-IBP, by combining the fast IBP bounds in the forward pass and a tight linear relaxation based bound, CROWN, in the backward pass. The proposed method is computationally efficient and consistently outperforms IBP baselines on training verifiably robust neural networks. We conduct large scale experiments using 53 models on MNIST, Fashion-MNIST and CIFAR datasets. On MNIST with ϵ=0.3 and ϵ=0.4 (ℓ_∞ norm distortion) we achieve 7.46% and 12.96% verified error on test set, respectively, outperforming previous certified defense methods.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/01/2021

Towards Evaluating and Training Verifiably Robust Neural Networks

Recent works have shown that interval bound propagation (IBP) can be use...
research
02/22/2020

Improving the Tightness of Convex Relaxation Bounds for Training Certifiably Robust Classifiers

Convex relaxations are effective for training and certifying neural netw...
research
05/28/2019

Probabilistically True and Tight Bounds for Robust Deep Neural Network Training

Training Deep Neural Networks (DNNs) that are robust to norm bounded adv...
research
02/28/2020

Automatic Perturbation Analysis on General Computational Graphs

Linear relaxation based perturbation analysis for neural networks, which...
research
06/17/2023

Understanding Certified Training with Interval Bound Propagation

As robustness verification methods are becoming more precise, training c...
research
05/25/2018

Training verified learners with learned verifiers

This paper proposes a new algorithmic framework,predictor-verifier train...
research
09/30/2019

Universal Approximation with Certified Networks

Training neural networks to be certifiably robust is a powerful defense ...

Please sign up or login with your details

Forgot password? Click here to reset