REVIEW 3 cited by
Adversarial Robustness of Deep Neural Networks: A Survey from a Formal Verification Perspective
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Neural networks have been widely applied in security applications such as spam and phishing detection, intrusion prevention, and malware detection. This black-box method, however, often has uncertainty and poor explainability in applications. Furthermore, neural networks themselves are often vulnerable to adversarial attacks. For those reasons, there is a high demand for trustworthy and rigorous methods to verify the robustness of neural network models. Adversarial robustness, which concerns the reliability of a neural network when dealing with maliciously manipulated inputs, is one of the hottest topics in security and machine learning. In this work, we survey existing literature in adversarial robustness verification for neural networks and collect 39 diversified research works across machine learning, security, and software engineering domains. We systematically analyze their approaches, including how robustness is formulated, what verification techniques are used, and the strengths and limitations of each technique. We provide a taxonomy from a formal verification perspective for a comprehensive understanding of this topic. We classify the existing techniques based on property specification, problem reduction, and reasoning strategies. We also demonstrate representative techniques that have been applied in existing studies with a sample model. Finally, we discuss open questions for future research.
Forward citations
Cited by 3 Pith papers
-
On AI Safety and Security Technical Debt in Engineering AI-Enabled Systems
The authors synthesize 31 AI technical debt types from 60 studies, map them to safety/security concerns, and propose 34 mitigation guidelines in the AITD-MAP framework.
-
Probabilistic Verification of Neural Networks via Efficient Probabilistic Hull Generation
A regression-tree-based method computes guaranteed bounds on the safe output probability for neural networks under probabilistic inputs by generating safe and unsafe hulls via boundary-aware sampling and prioritized r...
-
SoK: A Comprehensive Analysis of the Current Status of Neural Tangent Generalization Attacks with Research Directions
NTGA is the first clean-label generalization attack under black-box settings but is vulnerable to adversarial training and image transformations, with newer attacks outperforming it.
Discussion (0). Sign in to comment.