Provable Certificates for Adversarial Examples: Fitting a Ball in the Union of Polytopes

03/20/2019
by   Matt Jordan, et al.
16

We propose a novel method for computing exact pointwise robustness of deep neural networks for a number of ℓ_p norms. Our algorithm, GeoCert, finds the largest ℓ_p ball centered at an input point x_0, within which the output class of a given neural network with ReLU nonlinearities remains unchanged. We relate the problem of computing pointwise robustness of these networks to that of growing a norm ball inside a non-convex polytope. This is a challenging problem in general, as we discuss; however, we prove a useful structural result about the geometry of the piecewise linear components of ReLU networks. This result allows for an efficient convex decomposition of the problem. Specifically we show that if polytopes satisfy a technical condition that we call being 'perfectly-glued', then we can find the largest ball inside their union in polynomial time. Our method is efficient and can certify pointwise robustness for any norm where p is greater or equal to 1.

READ FULL TEXT

page 5

page 7

page 8

page 9

research
07/18/2023

Convex Geometry of ReLU-layers, Injectivity on the Ball and Local Reconstruction

The paper uses a frame-theoretic setting to study the injectivity of a R...
research
03/13/2023

The Localized Union-of-Balls Bifiltration

We propose an extension of the classical union-of-balls filtration of pe...
research
07/24/2023

On Maximizing the Distance to a Given Point over an Intersection of Balls II

In this paper the problem of maximizing the distance to a given fixed po...
research
05/31/2023

Optimal Sets and Solution Paths of ReLU Networks

We develop an analytical framework to characterize the set of optimal Re...
research
02/01/2019

Robustness Certificates Against Adversarial Examples for ReLU Networks

While neural networks have achieved high performance in different learni...
research
11/02/2017

Provable defenses against adversarial examples via the convex outer adversarial polytope

We propose a method to learn deep ReLU-based classifiers that are provab...
research
02/12/2020

Fast Geometric Projections for Local Robustness Certification

Local robustness ensures that a model classifies all inputs within an ϵ-...

Please sign up or login with your details

Forgot password? Click here to reset