This is not the latest version of this item. The latest version can be found here.
ON EXTENSIONS OF CLEVER: A NEURAL NETWORK ROBUSTNESS EVALUATION ALGORITHM
Name
1810.08640.pdf
Description
Submitted version
Size
126.38 KB
Format
Adobe PDF
Checksum (MD5)
aba1bebe43c2a59a1e5d6448fd028fa8
Author(s) • • • • •
Weng, Tsui-Wei
Zhang, Huan
Chen, Pin-Yu
Lozano, Aurelie
Hsieh, Cho-Jui
Daniel, Luca
Date Issued
November 2018
Publisher
IEEE
Citation
Weng, Tsui-Wei, Zhang, Huan, Chen, Pin-Yu, Lozano, Aurelie, Hsieh, Cho-Jui et al. 2018. "ON EXTENSIONS OF CLEVER: A NEURAL NETWORK ROBUSTNESS EVALUATION ALGORITHM."
Version
Original manuscript
Abstract
© 2018 IEEE. CLEVER (Cross-Lipschitz Extreme Value for nEtwork Robustness) is an Extreme Value Theory (EVT) based robustness score for large-scale deep neural networks (DNNs). In this paper, we propose two extensions on this robustness score. First, we provide a new formal robustness guarantee for classifier functions that are twice differentiable. We apply extreme value theory on the new formal robustness guarantee and the estimated robustness is called second-order CLEVER score. Second, we discuss how to handle gradient masking, a common defensive technique, using CLEVER with Backward Pass Differentiable Approximation (BPDA). With BPDA applied, CLEVER can evaluate the intrinsic robustness of neural networks of a broader class - networks with non-differentiable input transformations. We demonstrate the effectiveness of CLEVER with BPDA in experiments on a 121-layer Densenet model trained on the ImageNet dataset.
Terms of Use
Creative Commons Attribution-Noncommercial-Share Alike
Persistent DSpace Link
DOI of Published Version
10.1109/globalsip.2018.8646356