Certified Interpretability Robustness for Class Activation Mapping

by   Alex Gu, et al.

Interpreting machine learning models is challenging but crucial for ensuring the safety of deep networks in autonomous driving systems. Due to the prevalence of deep learning based perception models in autonomous vehicles, accurately interpreting their predictions is crucial. While a variety of such methods have been proposed, most are shown to lack robustness. Yet, little has been done to provide certificates for interpretability robustness. Taking a step in this direction, we present CORGI, short for Certifiably prOvable Robustness Guarantees for Interpretability mapping. CORGI is an algorithm that takes in an input image and gives a certifiable lower bound for the robustness of the top k pixels of its CAM interpretability map. We show the effectiveness of CORGI via a case study on traffic sign data, certifying lower bounds on the minimum adversarial perturbation not far from (4-5x) state-of-the-art attack methods.


page 3

page 13


Evaluating Adversarial Attacks on Driving Safety in Vision-Based Autonomous Vehicles

In recent years, many deep learning models have been adopted in autonomo...

Sensor Data Validation and Driving Safety in Autonomous Driving Systems

Autonomous driving technology has drawn a lot of attention due to its fa...

Grid-Centric Traffic Scenario Perception for Autonomous Driving: A Comprehensive Review

Grid-centric perception is a crucial field for mobile robot perception a...

Towards Improving Confidence in Autonomous Vehicle Software: A Study on Traffic Sign Recognition Systems

The application of artificial intelligence (AI) and data-driven decision...

Deep Learning-Based Autonomous Driving Systems: A Survey of Attacks and Defenses

The rapid development of artificial intelligence, especially deep learni...

Metrics for the Evaluation of localisation Robustness

Robustness and safety are crucial properties for the real-world applicat...

Robustness testing of AI systems: A case study for traffic sign recognition

In the last years, AI systems, in particular neural networks, have seen ...

Please sign up or login with your details

Forgot password? Click here to reset