Timezone: »
Poster
Fast and Effective Robustness Certification
Gagandeep Singh · Timon Gehr · Matthew Mirman · Markus Püschel · Martin Vechev
We present a new method and system, called DeepZ, for certifying neural network
robustness based on abstract interpretation. Compared to state-of-the-art automated
verifiers for neural networks, DeepZ: (i) handles ReLU, Tanh and Sigmoid activation functions, (ii) supports feedforward and convolutional architectures, (iii)
is significantly more scalable and precise, and (iv) and is sound with respect to
floating point arithmetic. These benefits are due to carefully designed approximations tailored to the setting of neural networks. As an example, DeepZ achieves a
verification accuracy of 97% on a large network with 88,500 hidden units under
$L_{\infty}$ attack with $\epsilon = 0.1$ with an average runtime of 133 seconds.
Author Information
Gagandeep Singh (ETH Zurich)
Timon Gehr (ETH Zurich)
Matthew Mirman (ETH Zurich)
Markus Püschel (ETH Zurich)
Martin Vechev (DeepCode and ETH Zurich, Switzerland)
More from the Same Authors
-
2021 : Bayesian Framework for Gradient Leakage »
Mislav Balunovic · Dimitar Dimitrov · Martin Vechev -
2021 Poster: Automated Discovery of Adaptive Attacks on Adversarial Defenses »
Chengyuan Yao · Pavol Bielik · Petar Tsankov · Martin Vechev -
2020 Poster: Learning Certified Individually Fair Representations »
Anian Ruoss · Mislav Balunovic · Marc Fischer · Martin Vechev -
2020 Poster: Certified Defense to Image Transformations via Randomized Smoothing »
Marc Fischer · Maximilian Baader · Martin Vechev -
2019 Poster: Powerset Convolutional Neural Networks »
Chris Wendler · Markus Püschel · Dan Alistarh -
2019 Poster: Beyond the Single Neuron Convex Barrier for Neural Network Certification »
Gagandeep Singh · Rupanshu Ganvir · Markus Püschel · Martin Vechev -
2019 Poster: Certifying Geometric Robustness of Neural Networks »
Mislav Balunovic · Maximilian Baader · Gagandeep Singh · Timon Gehr · Martin Vechev -
2018 Poster: Learning to Solve SMT Formulas »
Mislav Balunovic · Pavol Bielik · Martin Vechev -
2018 Oral: Learning to Solve SMT Formulas »
Mislav Balunovic · Pavol Bielik · Martin Vechev