English

Towards General Robustness Verification of MaxPool-based Convolutional Neural Networks via Tightening Linear Approximation

Computer Vision and Pattern Recognition 2024-06-04 v1

Abstract

The robustness of convolutional neural networks (CNNs) is vital to modern AI-driven systems. It can be quantified by formal verification by providing a certified lower bound, within which any perturbation does not alter the original input's classification result. It is challenging due to nonlinear components, such as MaxPool. At present, many verification methods are sound but risk losing some precision to enhance efficiency and scalability, and thus, a certified lower bound is a crucial criterion for evaluating the performance of verification tools. In this paper, we present MaxLin, a robustness verifier for MaxPool-based CNNs with tight linear approximation. By tightening the linear approximation of the MaxPool function, we can certify larger certified lower bounds of CNNs. We evaluate MaxLin with open-sourced benchmarks, including LeNet and networks trained on the MNIST, CIFAR-10, and Tiny ImageNet datasets. The results show that MaxLin outperforms state-of-the-art tools with up to 110.60% improvement regarding the certified lower bound and 5.13 ×\times speedup for the same neural networks. Our code is available at https://github.com/xiaoyuanpigo/maxlin.

Keywords

Cite

@article{arxiv.2406.00699,
  title  = {Towards General Robustness Verification of MaxPool-based Convolutional Neural Networks via Tightening Linear Approximation},
  author = {Yuan Xiao and Shiqing Ma and Juan Zhai and Chunrong Fang and Jinyuan Jia and Zhenyu Chen},
  journal= {arXiv preprint arXiv:2406.00699},
  year   = {2024}
}

Comments

Accepted to CVPR2024. Project page: https://github.com/xiaoyuanpigo/maxlin

R2 v1 2026-06-28T16:50:01.920Z