Reachability Analysis of Deep Neural Networks with Provable Guarantees
read the original abstract
Verifying correctness of deep neural networks (DNNs) is challenging. We study a generic reachability problem for feed-forward DNNs which, for a given set of inputs to the network and a Lipschitz-continuous function over its outputs, computes the lower and upper bound on the function values. Because the network and the function are Lipschitz continuous, all values in the interval between the lower and upper bound are reachable. We show how to obtain the safety verification problem, the output range analysis problem and a robustness measure by instantiating the reachability problem. We present a novel algorithm based on adaptive nested optimisation to solve the reachability problem. The technique has been implemented and evaluated on a range of DNNs, demonstrating its efficiency, scalability and ability to handle a broader class of networks than state-of-the-art verification approaches.
This paper has not been read by Pith yet.
Forward citations
Cited by 2 Pith papers
-
Reachability In Simple Neural Networks
Reachability for neural networks is NP-hard for single-hidden-layer networks with output dimension 1 and weights restricted to {-1,0,1}.
-
ReachNN: Reachability Analysis of Neural-Network Controlled Systems
ReachNN abstracts feedforward neural networks with Bernstein polynomials and provides error bounds to compute reachable sets for verifying neural-network controlled systems with general Lipschitz-continuous activation...
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.