Neural networks are vulnerable to adversarial attacks, i.e., small input perturbations can significantly affect the outputs of a neural network. In safety-critical environments, the inputs often contain noisy sensor data; hence, in this case, neural networks that are robust against input perturbations are required. To ensure safety, the robustness of a neural network must be formally verified. However, training and formally verifying robust neural networks is challenging. We address both of these challenges by employing, for the first time, an end-to-end set-based training procedure that trains robust neural networks for formal verification. Our training procedure trains neural networks, which can be easily verified using simple polynomial-time verification algorithms. Moreover, our extensive evaluation demonstrates that our set-based training procedure effectively trains robust neural networks, which are easier to verify. Set-based trained neural networks consistently match or outperform those trained with state-of-the-art robust training approaches.
翻译:神经网络易受对抗攻击的影响,即微小的输入扰动会显著改变神经网络的输出。在安全关键环境中,输入常包含含噪声的传感器数据,因此需要能够抵御输入扰动的鲁棒神经网络。为确保安全性,必须对神经网络的鲁棒性进行形式化验证。然而,训练和形式化验证鲁棒神经网络极具挑战性。我们首次采用端到端的基于集合的训练流程来应对这两项挑战——该流程可训练出易于形式化验证的鲁棒神经网络。我们的训练流程产生的神经网络,能通过简单的多项式时间验证算法进行高效验证。此外,广泛评估表明,我们的基于集合训练方法能有效训练出更易验证的鲁棒神经网络。基于集合训练的神经网络在性能上始终能与采用最先进鲁棒训练方法训练的模型媲美或更优。