Towards Safe AI: Sandboxing DNNs-Based Controllers in Stochastic Games
Bingzhuo Zhong, Hongpeng Cao, Majid Zamani, Marco Caccamo
Abstract
Nowadays, AI-based techniques, such as deep neural networks (DNNs), are widely deployed in autonomous systems for complex mission requirements (e.g., motion planning in robotics). However, DNNs-based controllers are typically very complex, and it is very hard to formally verify their correctness, potentially causing severe risks for safety-critical autonomous systems. In this paper, we propose a construction scheme for a so-called Safe-visor architecture to sandbox DNNs-based controllers. Particularly, we consider the construction under a stochastic game framework to provide a system-level safety guarantee which is robust to noises and disturbances. A supervisor is built to check the control inputs provided by a DNNs-based controller and decide whether to accept them. Meanwhile, a safety advisor is running in parallel to provide fallback control inputs in case the DNN-based controller is rejected. We demonstrate the proposed approaches on a quadrotor employing an unverified DNNs-based controller.
BibTeX
@article{Zhong_Cao_Zamani_Caccamo_2023, title={Towards Safe AI: Sandboxing DNNs-Based Controllers in Stochastic Games}, volume={37}, url={https://ojs.aaai.org/index.php/AAAI/article/view/26789}, DOI={10.1609/aaai.v37i12.26789}, abstractNote={Nowadays, AI-based techniques, such as deep neural networks (DNNs), are widely deployed in autonomous systems for complex mission requirements (e.g., motion planning in robotics). However, DNNs-based controllers are typically very complex, and it is very hard to formally verify their correctness, potentially causing severe risks for safety-critical autonomous systems. In this paper, we propose a construction scheme for a so-called Safe-visor architecture to sandbox DNNs-based controllers. Particularly, we consider the construction under a stochastic game framework to provide a system-level safety guarantee which is robust to noises and disturbances. A supervisor is built to check the control inputs provided by a DNNs-based controller and decide whether to accept them. Meanwhile, a safety advisor is running in parallel to provide fallback control inputs in case the DNN-based controller is rejected. We demonstrate the proposed approaches on a quadrotor employing an unverified DNNs-based controller.}, number={12}, journal={Proceedings of the AAAI Conference on Artificial Intelligence}, author={Zhong, Bingzhuo and Cao, Hongpeng and Zamani, Majid and Caccamo, Marco}, year={2023}, month={Jun.}, pages={15340-15349} }