Verification of neural networks against convolutional perturbations via parameterised kernels
File(s) main.pdf (328.73 KB)
Accepted version
Author(s)
Brückner, Benedikt
Lomuscio, Alessio
Type
Conference Paper
Abstract
We develop a method for the efficient verification of neural
networks against convolutional perturbations such as blurring or sharpening. To define input perturbations, we use well-known camera shake, box blur and sharpen kernels. We linearly parameterise these kernels in a way that allows for a
variation of the perturbation strength while preserving desired kernel properties. To facilitate their use in neural network verification, we develop an efficient way of convolving a given input with the parameterised kernels. The result of this convolution can be used to encode the perturbation in a verification setting by prepending a linear layer to a given network. This leads to tight bounds and a high effectiveness in the resulting verification step. We add further precision by employing in-put splitting as a branching strategy. We demonstrate that we are able to verify robustness on a number of standard bench-marks where the baseline is unable to provide any safety certificates. To the best of our knowledge, this is the first solution for verifying robustness against specific convolutional perturbations such as camera shake.
networks against convolutional perturbations such as blurring or sharpening. To define input perturbations, we use well-known camera shake, box blur and sharpen kernels. We linearly parameterise these kernels in a way that allows for a
variation of the perturbation strength while preserving desired kernel properties. To facilitate their use in neural network verification, we develop an efficient way of convolving a given input with the parameterised kernels. The result of this convolution can be used to encode the perturbation in a verification setting by prepending a linear layer to a given network. This leads to tight bounds and a high effectiveness in the resulting verification step. We add further precision by employing in-put splitting as a branching strategy. We demonstrate that we are able to verify robustness on a number of standard bench-marks where the baseline is unable to provide any safety certificates. To the best of our knowledge, this is the first solution for verifying robustness against specific convolutional perturbations such as camera shake.
Date Acceptance
2024-12-14
Citation
Proceedings of the 39th AAAI Conference on Artificial Intelligence (AAAI25)
Publisher
AAAI
Journal / Book Title
Proceedings of the 39th AAAI Conference on Artificial Intelligence (AAAI25)
Copyright Statement
Copyright © 2025, Association for the Advancement of Artificial Intelligence. This paper is embargoed until publication.
Source
AAAI Conference on Artificial Intelligence (AAAI25)
Publication Status
Accepted
Start Date
2025-02-27
Finish Date
2025-03-04
Coverage Spatial
Philadelphia, PA, USA
