Portfolio solver for verifying Binarized Neural Networks

Gergely Kovásznai, Krisztián Gajdár, Nina Narodytska
{"title":"Portfolio solver for verifying Binarized Neural Networks","authors":"Gergely Kovásznai, Krisztián Gajdár, Nina Narodytska","doi":"10.33039/AMI.2021.03.007","DOIUrl":null,"url":null,"abstract":"Although deep learning is a very successful AI technology, many concerns have been raised about to what extent the decisions making process of deep neural networks can be trusted. Verifying of properties of neural networks such as adversarial robustness and network equivalence sheds light on the trustiness of such systems. We focus on an important family of deep neural networks, the Binarized Neural Networks (BNNs) that are useful in resourceconstrained environments, like embedded devices. We introduce our portfolio solver that is able to encode BNN properties for SAT, SMT, and MIP solvers and run them in parallel, in a portfolio setting. In the paper we propose all the corresponding encodings of different types of BNN layers as well as BNN properties into SAT, SMT, cardinality constrains, and pseudo-Boolean constraints. Our experimental results demonstrate that our solver is capable of verifying adversarial robustness of medium-sized BNNs in reasonable time and seems to scale for larger BNNs. We also report on experiments on network equivalence with promising results.","PeriodicalId":8040,"journal":{"name":"Applied Medical Informaticvs","volume":"53 1","pages":"183-200"},"PeriodicalIF":0.0000,"publicationDate":"2021-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Applied Medical Informaticvs","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.33039/AMI.2021.03.007","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

Although deep learning is a very successful AI technology, many concerns have been raised about to what extent the decisions making process of deep neural networks can be trusted. Verifying of properties of neural networks such as adversarial robustness and network equivalence sheds light on the trustiness of such systems. We focus on an important family of deep neural networks, the Binarized Neural Networks (BNNs) that are useful in resourceconstrained environments, like embedded devices. We introduce our portfolio solver that is able to encode BNN properties for SAT, SMT, and MIP solvers and run them in parallel, in a portfolio setting. In the paper we propose all the corresponding encodings of different types of BNN layers as well as BNN properties into SAT, SMT, cardinality constrains, and pseudo-Boolean constraints. Our experimental results demonstrate that our solver is capable of verifying adversarial robustness of medium-sized BNNs in reasonable time and seems to scale for larger BNNs. We also report on experiments on network equivalence with promising results.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
验证二值化神经网络的组合求解器
尽管深度学习是一项非常成功的人工智能技术,但人们对深度神经网络的决策过程在多大程度上可以信任提出了许多担忧。对神经网络的对抗鲁棒性和网络等价性等特性的验证,揭示了神经网络系统的可信性。我们专注于一个重要的深度神经网络家族,二值化神经网络(bnn),它在资源受限的环境中很有用,比如嵌入式设备。我们介绍我们的投资组合求解器,它能够为SAT、SMT和MIP求解器编码BNN属性,并在投资组合设置中并行运行它们。本文提出了不同类型的BNN层的所有相应编码以及BNN的性质,包括SAT约束、SMT约束、基数约束和伪布尔约束。我们的实验结果表明,我们的求解器能够在合理的时间内验证中型bnn的对抗鲁棒性,并且似乎可以扩展到更大的bnn。我们还报道了网络等价的实验,结果很有希望。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Comparison of national and foreign normative documents on radiographic control. Advantages and disadvantages. Pembelajaran Membaca Teks Drama dengan Menggunakan Metode Quantum dikelas 5 Min 6 Pidie ISU DAN TREN PENELITIAN PENGEMBANGAN BAHAN AJAR BAHASA ARAB TAHUN 2017-2020 TATHAWWUR MU’TAQADĀT AL-THULLĀB HAULA TA’ALLUM AL-LUGHAH FI BARNĀMAJ DAURAH AL-LUGHAH AL-ARABIYYAH AL-MUKATSTSAFAH ‘ABR AL-JINSI WA AL-KHALFIYĀTI AL-TARBAWIYYAH: DIRĀSAH MAQTA’IYYAH WA THŪLIYYAH ISTIKHDĀM AL-KITĀB AL ‘ARABIYATI LĪ AL-NĀSYI'IN LI MAHMŪD ISMĀIL SHĪNĪ WA AL-ASHDIQĀ' FI TARQIYAT MAHĀRAT AL-LUGAT AL- ARABIYAT LADA AL-TULLĀBI FĪ AL-MADRASAT AL MUTAWASSITHAT AL-FAJAR MATARAM
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1