Measuring Neural Net Robustness with Constraints

05/24/2016
by   Osbert Bastani, et al.
0

Despite having high accuracy, neural nets have been shown to be susceptible to adversarial examples, where a small perturbation to an input can cause it to become mislabeled. We propose metrics for measuring the robustness of a neural net and devise a novel algorithm for approximating these metrics based on an encoding of robustness as a linear program. We show how our metrics can be used to evaluate the robustness of deep neural nets with experiments on the MNIST and CIFAR-10 datasets. Our algorithm generates more informative estimates of robustness metrics compared to estimates based on existing algorithms. Furthermore, we show how existing approaches to improving robustness "overfit" to adversarial examples generated using a specific algorithm. Finally, we show that our techniques can be used to additionally improve neural net robustness both according to the metrics that we propose, but also according to previously proposed metrics.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
09/13/2017

EAD: Elastic-Net Attacks to Deep Neural Networks via Adversarial Examples

Recent studies have highlighted the vulnerability of deep neural network...
research
08/16/2016

Towards Evaluating the Robustness of Neural Networks

Neural networks provide state-of-the-art results for most machine learni...
research
03/09/2023

Evaluating the Robustness of Conversational Recommender Systems by Adversarial Examples

Conversational recommender systems (CRSs) are improving rapidly, accordi...
research
12/01/2020

Measuring Network Robustness by Average Network Flow

Infrastructure networks such as the Internet backbone and power grids ar...
research
10/29/2019

Distribution Density, Tails, and Outliers in Machine Learning: Metrics and Applications

We develop techniques to quantify the degree to which a given (training ...
research
02/06/2019

Toward A Neuro-inspired Creative Decoder

Creativity, a process that generates novel and valuable ideas, involves ...
research
11/30/2022

Efficient Adversarial Input Generation via Neural Net Patching

The adversarial input generation problem has become central in establish...

Please sign up or login with your details

Forgot password? Click here to reset