ICLR 2019poster50 citations

Verification of Non-Linear Specifications for Neural Networks

Chongli Qin, Krishnamurthy (Dj) Dvijotham, Brendan O'Donoghue, Rudy Bunel, Robert Stanforth, Sven Gowal, Jonathan Uesato, Grzegorz Swirszcz

Abstract

Prior work on neural network verification has focused on specifications that are linear functions of the output of the network, e.g., invariance of the classifier output under adversarial perturbations of the input. In this paper, we extend verification algorithms to be able to certify richer properties of neural networks. To do this we introduce the class of convex-relaxable specifications, which constitute nonlinear specifications that can be verified using a convex relaxation. We show that a number of important properties of interest can be modeled within this class, including conservation of energy in a learned dynamics model of a physical system; semantic consistency of a classifier's output labels under adversarial perturbations and bounding errors in a system that predicts the summation of handwritten digits. Our experimental evaluation shows that our method is able to effectively verify these specifications. Moreover, our evaluation exposes the failure modes in models which cannot be verified to satisfy these specifications. Thus, emphasizing the importance of training models not just to fit training data but also to be consistent with specifications.

VerificationConvex OptimizationAdversarial Robustness
BibTeX
@inproceedings{
qin2018verification,
title={Verification of Non-Linear Specifications for Neural Networks},
author={Chongli Qin and Krishnamurthy (Dj) Dvijotham and Brendan O'Donoghue and Rudy Bunel and Robert Stanforth and Sven Gowal and Jonathan Uesato and Grzegorz Swirszcz and Pushmeet Kohli},
booktitle={International Conference on Learning Representations},
year={2019},
url={https://openreview.net/forum?id=HyeFAsRctQ},
}
Verification of Non-Linear Specifications for Neural Networks · ICLR 2019