Published May 18, 2020 | Version v1

Probabilistic Safety for Bayesian Neural Networks

  • 1. University of Oxford

Description

We study probabilistic safety for BayesianNeural Networks (BNNs) under adversarial in-put perturbations. Given a compact set of input points,T⊆Rm, we study the probability w.r.t. the BNN posterior that all the pointsinTare mapped to the same region S in theoutput space. In particular, this can be usedto evaluate the probability that a network sam-pled from the BNN is vulnerable to adversarialattacks. We rely on relaxation techniques from non-convex optimization to develop a methodfor computing a lower bound on probabilis-tic safety for BNNs, deriving explicit procedures for the case of interval and linear function propagation techniques. We apply ourmethods to BNNs trained on a regression task,airborne collision avoidance, and MNIST, empirically showing that our approach allows oneto certify probabilistic safety of BNNs withthousands of neurons.

Notes

This project has received funding from the European Union's Horizon 2020 research and innovation programme under the Marie Skłodowska-Curie grant agreement No 722022

Files

UAI2020.pdf

Files (960.5 kB)

Name Size Download all
md5:8cbce50aae19dd41eee782dc303d949f
960.5 kB Preview Download