Robust neural networks: verification, training, and repair
File(s)
Author(s)
Henriksen, Patrick
Type
Thesis
Abstract
Neural networks are fragile; even tiny perturbations of their inputs can lead to severe undesired changes to their outputs. The fragility of neural networks is of particular concern in safety- critical applications such as autonomous vehicles and medical imaging, where model failures can have serious consequences. This thesis proposes several methods for evaluating and improving the robustness of neural networks.
First, we propose a formal verification method that may be deployed post-training to evaluate the robustness of neural networks. An implementation of the method achieved 1—2 orders of magnitude speed-up compared to contemporary approaches. Moreover, the method was the first formal verification approach to support verification against a class of smooth intensity perturbations modelled by bias fields.
Next, this thesis presents novel methods for robust training, verification-friendly design, and repair of neural networks. The robust training method produces networks that are robust to bias field perturbations; in experiments, networks trained with the method achieved up to 31% higher certified robustness against bias field perturbations than the baseline approaches. The verification-friendly design of networks improves verifiability by replacing standard ReLU activation functions with parametric ReLUs that are regularised during training; the resulting networks experienced 30–100% fewer timeouts during formal verification compared to standard ReLU networks. The repair method repairs misclassifications in neural networks post-training without access to the training data; empirical results report accuracy drops that are up to 90% smaller compared to alternative state-of-the-art approaches.
Finally, this thesis presents the VeriNet toolkit, which implements the verification and robust training methods discussed above. VeriNet was evaluated in the second and third interna- tional verification of neural networks competitions. The competitions evaluated verification toolkits based on their runtime, scalability to large networks, and supported network opera- tions and architectures. VeriNet achieved second place in the 2021 competition and third place in 2022.
First, we propose a formal verification method that may be deployed post-training to evaluate the robustness of neural networks. An implementation of the method achieved 1—2 orders of magnitude speed-up compared to contemporary approaches. Moreover, the method was the first formal verification approach to support verification against a class of smooth intensity perturbations modelled by bias fields.
Next, this thesis presents novel methods for robust training, verification-friendly design, and repair of neural networks. The robust training method produces networks that are robust to bias field perturbations; in experiments, networks trained with the method achieved up to 31% higher certified robustness against bias field perturbations than the baseline approaches. The verification-friendly design of networks improves verifiability by replacing standard ReLU activation functions with parametric ReLUs that are regularised during training; the resulting networks experienced 30–100% fewer timeouts during formal verification compared to standard ReLU networks. The repair method repairs misclassifications in neural networks post-training without access to the training data; empirical results report accuracy drops that are up to 90% smaller compared to alternative state-of-the-art approaches.
Finally, this thesis presents the VeriNet toolkit, which implements the verification and robust training methods discussed above. VeriNet was evaluated in the second and third interna- tional verification of neural networks competitions. The competitions evaluated verification toolkits based on their runtime, scalability to large networks, and supported network opera- tions and architectures. VeriNet achieved second place in the 2021 competition and third place in 2022.
Version
Open Access
Date Issued
2023-07
Date Awarded
2023-12
Copyright Statement
Creative Commons Attribution NonCommercial Licence
License URL
Advisor
Lomuscio, Alessio
Sponsor
UK Research and Innovation
Grant Number
EP/S023356/1
Publisher Department
Computing
Publisher Institution
Imperial College London
Qualification Level
Doctoral
Qualification Name
Doctor of Philosophy (PhD)
