English

CC-Cert: A Probabilistic Approach to Certify General Robustness of Neural Networks

Machine Learning 2022-08-16 v2 Artificial Intelligence

Abstract

In safety-critical machine learning applications, it is crucial to defend models against adversarial attacks -- small modifications of the input that change the predictions. Besides rigorously studied p\ell_p-bounded additive perturbations, recently proposed semantic perturbations (e.g. rotation, translation) raise a serious concern on deploying ML systems in real-world. Therefore, it is important to provide provable guarantees for deep learning models against semantically meaningful input transformations. In this paper, we propose a new universal probabilistic certification approach based on Chernoff-Cramer bounds that can be used in general attack settings. We estimate the probability of a model to fail if the attack is sampled from a certain distribution. Our theoretical findings are supported by experimental results on different datasets.

Keywords

Cite

@article{arxiv.2109.10696,
  title  = {CC-Cert: A Probabilistic Approach to Certify General Robustness of Neural Networks},
  author = {Mikhail Pautov and Nurislam Tursynbek and Marina Munkhoeva and Nikita Muravev and Aleksandr Petiushko and Ivan Oseledets},
  journal= {arXiv preprint arXiv:2109.10696},
  year   = {2022}
}

Comments

In Proceedings of AAAI-22, the Thirty-Sixth AAAI Conference on Artificial Intelligence