Verifying Properties of Binary Neural Networks Using Sparse Polynomial Optimization - Polynomial OPtimization
Poster De Conférence Année : 2024

Verifying Properties of Binary Neural Networks Using Sparse Polynomial Optimization

Résumé

This work explores methods for verifying the properties of Binary Neural Networks (BNNs), focusing on robustness against adversarial attacks. Despite their lower computational and memory needs, BNNs, like their full-precision counterparts, are also sensitive to input perturbations. Established methods for solving this problem are predominantly based on Satisfiability Modulo Theories (SMT) and Mixed-Integer Linear Programming (MILP) techniques, which often face scalability issues. We introduce an alternative approach using Semidefinite Programming (SDP) relaxations derived from sparse Polynomial Optimization (POP). Our approach, compatible with continuous input space, not only mitigates numerical issues associated with floating-point calculations but also enhances verification scalability through the strategic use of tighter first-order semidefinite relaxations. We demonstrate the effectiveness of our method in verifying robustness against both ∥.∥ ∞ and ∥.∥ 2 -based adversarial attacks.

Fichier principal
Vignette du fichier
RTDAYS-Srecko-PosterPOP4BNN (1).pdf (922.54 Ko) Télécharger le fichier
Origine Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-04720757 , version 1 (04-10-2024)

Identifiants

  • HAL Id : hal-04720757 , version 1

Citer

Srećko Đurašinović, Jianting Yang, Jean-Bernard Lasserre, Victor Magron, Jun Zhao. Verifying Properties of Binary Neural Networks Using Sparse Polynomial Optimization. R&T Days 2024, Jul 2024, Toulouse (FRANCE), France. 2024. ⟨hal-04720757⟩
3 Consultations
0 Téléchargements

Partager

More