Evaluating robustness of neural networks
Name
1227782217-MIT.pdf
Size
3.2 MB
Format
Adobe PDF
Checksum (MD5)
c5acecce59ee7ec94a69fc1ab11c4d30
Author(s)
Weng, Tsui-Wei(Tsui-Wei Lily)
Advisor(s)
Luca Daniel.
Date Issued
2020
Publisher
Massachusetts Institute of Technology
Abstract
The robustness of neural networks to adversarial examples has received great attention due to security implications. Despite various attack approaches to crafting visually imperceptible adversarial examples, little has been developed towards a comprehensive metric of robustness. This thesis is dedicated to developing several robustness quantification frameworks for deep neural networks against both adversarial and non-adversarial input perturbations, including the first robustness score CLEVER, efficient certification algorithms Fast-Lin, CROWN, CNN-Cert, and probabilistic robustness verification algorithm PROVEN. Our proposed approaches are computationally efficient and provide good quality of robustness estimates and certificates as demonstrated by extensive experiments on MNIST, CIFAR and ImageNet.
Description
Thesis: Ph. D., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, September, 2020
Cataloged from student-submitted PDF of thesis.
Includes bibliographical references (pages 135-143).
Subjects
Electrical Engineering and Computer Science.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
MIT theses may be protected by copyright. Please reuse MIT thesis content according to the MIT Libraries Permissions Policy, which is available through the URL provided.
Persistent DSpace Link