引用本文:刘宗鑫,迟智名,赵梦宇,黄承超,黄小炜,蔡少伟,张立军,杨鹏飞.神经网络的增量验证.软件学报,2025,36(8):3444-3461
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 1731次   下载 1612 本文二维码信息
码上扫一扫!
分享到: 微信 更多
神经网络的增量验证
刘宗鑫1,2,3, 迟智名1,2,3, 赵梦宇1,2,3, 黄承超4, 黄小炜5, 蔡少伟1,2,3, 张立军1,2,3, 杨鹏飞1,2
1.基础软件与系统重点实验室 (中国科学院 软件研究所), 北京 100190;2.计算机科学国家重点实验室 (中国科学院 软件研究所), 北京 100190;3.中国科学院大学, 北京 100049;4.中国科学院大学南京学院, 江苏 南京 211135;5.University of Liverpool, Liverpool L69 3BX, UK
摘要:
约束求解是验证神经网络的基础方法. 在人工智能安全领域, 为了修复或攻击等目的, 常需要对神经网络的结构和参数进行修改. 面对此类需求, 提出神经网络的增量验证问题, 旨在判断修改后的神经网络是否仍保持安全性质. 针对这类问题, 基于Reluplex框架提出了一种增量可满足性模理论算法DeepInc. 该算法利用旧求解过程中关键计算格局的特征, 启发式地检查关键计算格局是否适用于证明修改后的神经网络. 实验结果显示, DeepInc的效率在大多数情况下都优于Marabou. 此外, 即使与最先进的验证工具α, β-CROWN相比, 对于修改前后均未满足预设安全性质的网络, DeepInc也实现了显著的加速.
关键词:  可满足性模理论  深度神经网络  增量约束求解  局部鲁棒  形式化验证
DOI:10.13328/j.cnki.jos.007344
分类号:
基金项目:中国科学院基础研究青年团队计划 (YSBR-040); 中国科学院软件研究所新培育方向项目(ISCAS-PYFX-202201); 中国科学院软件研究所基础研究项目 (ISCAS-JCZD-202302)
Incremental Verification for Neural Network
LIU Zong-Xin1,2,3, CHI Zhi-Ming1,2,3, ZHAO Meng-Yu1,2,3, HUANG Cheng-Chao4, HUANG Xiao-Wei5, CAI Shao-Wei1,2,3, ZHANG Li-Jun1,2,3, YANG Peng-Fei1,2
1.Key Laboratory of System Software (Institute of Software, Chinese Academy of Sciences), Beijing 100190, China;2.State Key Laboratory of Computer Science (Institute of Software, Chinese Academy of Sciences), Beijing 100190, China;3.University of Chinese Academy of Sciences, Beijing 100049, China;4.University of Chinese Academy of Sciences, Nanjing, Nanjing 211135, China;5.University of Liverpool, Liverpool L69 3BX, UK
Abstract:
Constraint solving is a fundamental approach for verifying deep neural network (DNN). In the field of AI safety, DNNs often undergo modifications in their structure and parameters for purposes such as repair or attack. In such scenarios, the problem of incremental DNN verification is proposed, which aims to determine whether a safety property still holds after the DNN has been modified. To address this, an incremental satisfiability modulo theory (SMT) algorithm based on the Reluplex framework is presented. The proposed algorithm, DeepInc, leverages the key features of the configurations from the previous solving procedure, heuristically checking whether these features can be applied to prove the correctness of the modified DNN. Experimental results demonstrate that DeepInc outperforms Marabou in terms of efficiency in most cases. Moreover, for cases where the safety property is violated both before and after modification, DeepInc achieves significantly faster performance, even when compared to the state-of-the-art verifier α, β-CROWN.
Key words:  satisfiability module theory  deep neural network (DNN)  incremental constraint solving  local robustness  formal verification

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: