Probabilistic Safety for Bayesian Neural Networks
Authors/Creators
- 1. University of Oxford
Description
We study probabilistic safety for BayesianNeural Networks (BNNs) under adversarial in-put perturbations. Given a compact set of input points,T⊆Rm, we study the probability w.r.t. the BNN posterior that all the pointsinTare mapped to the same region S in theoutput space. In particular, this can be usedto evaluate the probability that a network sam-pled from the BNN is vulnerable to adversarialattacks. We rely on relaxation techniques from non-convex optimization to develop a methodfor computing a lower bound on probabilis-tic safety for BNNs, deriving explicit procedures for the case of interval and linear function propagation techniques. We apply ourmethods to BNNs trained on a regression task,airborne collision avoidance, and MNIST, empirically showing that our approach allows oneto certify probabilistic safety of BNNs withthousands of neurons.
Notes
Files
UAI2020.pdf
Files
(960.5 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:8cbce50aae19dd41eee782dc303d949f
|
960.5 kB | Preview Download |