Back to Search Start Over

Portfolio solver for verifying Binarized Neural Networks

Authors :
Nina Narodytska
Gergely Kovásznai
Krisztian Gajdar
Source :
Annales Mathematicae et Informaticae. 53:183-200
Publication Year :
2021
Publisher :
Annales Mathematicae et Informaticae - AMI, 2021.

Abstract

Although deep learning is a very successful AI technology, many concerns have been raised about to what extent the decisions making process of deep neural networks can be trusted. Verifying of properties of neural networks such as adversarial robustness and network equivalence sheds light on the trustiness of such systems. We focus on an important family of deep neural networks, the Binarized Neural Networks (BNNs) that are useful in resourceconstrained environments, like embedded devices. We introduce our portfolio solver that is able to encode BNN properties for SAT, SMT, and MIP solvers and run them in parallel, in a portfolio setting. In the paper we propose all the corresponding encodings of different types of BNN layers as well as BNN properties into SAT, SMT, cardinality constrains, and pseudo-Boolean constraints. Our experimental results demonstrate that our solver is capable of verifying adversarial robustness of medium-sized BNNs in reasonable time and seems to scale for larger BNNs. We also report on experiments on network equivalence with promising results.

Details

ISSN :
17876117
Volume :
53
Database :
OpenAIRE
Journal :
Annales Mathematicae et Informaticae
Accession number :
edsair.doi.dedup.....98cea4b18431e93f5cb9301e160ac7b6