REVIEW 2 cited by
A Statistical Approach to Assessing Neural Network Robustness
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
We present a new approach to assessing the robustness of neural networks based on estimating the proportion of inputs for which a property is violated. Specifically, we estimate the probability of the event that the property is violated under an input model. Our approach critically varies from the formal verification framework in that when the property can be violated, it provides an informative notion of how robust the network is, rather than just the conventional assertion that the network is not verifiable. Furthermore, it provides an ability to scale to larger networks than formal verification approaches. Though the framework still provides a formal guarantee of satisfiability whenever it successfully finds one or more violations, these advantages do come at the cost of only providing a statistical estimate of unsatisfiability whenever no violation is found. Key to the practical success of our approach is an adaptation of multi-level splitting, a Monte Carlo approach for estimating the probability of rare events, to our statistical robustness framework. We demonstrate that our approach is able to emulate formal verification procedures on benchmark problems, while scaling to larger networks and providing reliable additional information in the form of accurate estimates of the violation probability.
Forward citations
Cited by 2 Pith papers
-
Safe Start: Configuring Optimization Algorithms for Decision-Making under Extreme Risks
Safe-start initialization, combined with efficient gradient estimators, guarantees sub-exponential sample complexity for SGD in rare-event optimization; without it, exponential complexity can be unavoidable.
-
A Survey on the Verification of Reinforcement Learning Policies
A unifying taxonomy of post-training RL-policy verification methods along formal/probabilistic, step-wise/multi-step, and guarantee-strength axes, plus benchmark-based tool-selection guidance.
Discussion (0). Continue with ORCID to comment.