IP Library › Granted Patent US 12,468,942
Granted Patent B2
US 12,468,942 · App. 17/869,979 · Granted Nov 11, 2025

Method for training and/or verifying a robustness of an artificial neural network

Inventor: Frank Schmidt (Leonberg, DE)
Assignee: ROBERT BOSCH GMBH
G06N3/08G06V10/761G06V10/776G06V10/82B60W40/02G06N3/082G06T2207/10016G06T2207/20081G06T2207/20084G06V10/454G06V10/764G06V20/56G06V20/58H04N19/85
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,468,942
App. No.
17/869,979
Granted
Nov 11, 2025
Kind
B2
Abstract

A device, a method and a computer program for training and/or verifying the robustness of an artificial neural network. The artificial neural network is designed to determine an output variable. The method includes: predefining an input variable for the network which has a plurality of dimensions. For each dimension of the input variable or for each dimension of an output of a linear layer of the artificial neural network without an activation function to which the input variable is mapped by the artificial neural network, the method includes a determination of an upper input variable limit for which a disturbance variable model by which the input variable is able to be mapped to a disturbed input variable has the highest possible value in the dimension, and a determination of a lower input variable limit for which the disturbance variable model has the lowest value possible in the dimension.

Claims (45)

1 . A method for training and/or verifying a robustness of an artificial neural network in which the artificial neural network is configured to determine an output variable, the method comprising the following steps:

predefining an input variable for the artificial neural network that has a plurality of dimensions, for each dimension of the input variable or for each dimension of an output of a linear layer of the artificial neural network without an activation function to which the input variable is mapped by the artificial neural network, performing:

determining an upper input variable limit for which a disturbance model by which the input variable is able to be mapped to a disturbed input variable has a highest possible value in the dimension, and

determining a lower input variable limit for which the disturbance variable model has a lowest possible value in the dimension;

for each dimension of the output variable, performing:

determining a lower output variable limit for the output variable with values from a value range restricted by the lower input variable limits and the upper variable limits, and

determining an upper output variable limit for the output variable with the values from the value range restricted by the upper input variable limits and the lower input variable limits;

determining a lowest possible value of a real-valued function with values from a value range restricted by the lower output variable limit and the upper output variable limit;

determining a highest possible value of the real-valued function with values from the value range restricted by the lower output variable limit and the upper output variable limit; and

determining an output that confirms a robustness of the network when the lowest possible value and the highest possible value lie within a predefined interval of permissible values.

2 . The method as recited in claim 1 , wherein the input variable represents a digital image or a video or a radar image or a LiDAR image or an ultrasonic image or an infrared image.

3 . The method as recited in claim 1 , wherein the output variable represents a signal for actuating a physical system or a computer-controlled machine or a data transmission system or a robot or a vehicle or a household appliance or a driven tool of a production machine or a personal assistance system or an access control system or a monitoring system or a medical imaging system.

4 . The method as recited in claim 1 , wherein:

the output variable classifies sensor data for detecting objects in the sensor data or for a semantic segmentation, or

the output variable provides a regression for sensor data for detection of objects in the sensor data or for a semantic segmentation; and

wherein the objects represent markings or objects on or of road surfaces, including objects representing street signs or pedestrians or vehicles.

5 . The method as recited in claim 1 , wherein for each dimension of the input variable, the lower input variable limit of the dimension for which a first scalar product of a negative unit vector of the dimension with the input variable has the highest possible value is determined, and for each dimension of the input variable, the upper input variable limit of the dimension for which a second scalar product of a unit vector of the dimension with the input variable has the highest possible value is determined.

6 . The method as recited in claim 5 , wherein the artificial neural network provides a bias for the input variable or the output, the lower input variable limit and the upper input variable limit being corrected as a function of the bias.

7 . The method as recited in claim 1 , wherein the output of the linear layer of the artificial neural network without an activation function is defined by a matrix, and for each dimension of the output, a first product is defined which is determined by a multiplication of a negative transpose of the matrix with a unit vector of the dimension, and the method provides that the lower input variable limit of the dimension for which a first scalar product of the first product with the input variable has a highest possible value is determined, and for each dimension of the output, a second product is defined which is determined by a multiplication of a transpose of the matrix with the unit vector of the dimension, and the method provides that the upper input variable limit of the dimension for which a second scalar product of the second product with the input variable has the highest possible value is determined.

8 . The method as recited in claim 6 , wherein the linear layer of the artificial neural network without an activation function is an input layer of the artificial neural network, or a multitude of linear layers without an activation function is situated between an input of the artificial neural network and the output of the linear layer of the artificial neural network without an activation function.

9 . The method as recited in claim 1 , wherein the input variable is determined as a function of a measured signal or is selected from a value range.

10 . The method as recited in claim 1 , wherein when the lowest possible value or the highest possible value lies outside the predefined interval of permissible values or on its boundary, a value from an interval between the lowest possible value and the highest possible value is determined that has the largest possible distance from the interval, and the network is trained to reduce the distance.

11 . A device, comprising:

at least one processor device for training and/or verifying a robustness of an artificial neural network in which the artificial neural network is configured to determine an output variable, the at least one processor configured to:

predefine an input variable for the artificial neural network that has a plurality of dimensions, for each dimension of the input variable or for each dimension of an output of a linear layer of the artificial neural network without an activation function to which the input variable is mapped by the artificial neural network:

determine an upper input variable limit for which a disturbance model by which the input variable is able to be mapped to a disturbed input variable has a highest possible value in the dimension, and

determine a lower input variable limit for which the disturbance variable model has a lowest possible value in the dimension;

for each dimension of the output variable:

determine a lower output variable limit for the output variable with values from a value range restricted by the lower input variable limits and the upper variable limits, and

determine an upper output variable limit for the output variable with the values from the value range restricted by the upper input variable limits and the lower input variable limits;

determine a lowest possible value of a real-valued function with values from a value range restricted by the lower output variable limit and the upper output variable limit;

determine a highest possible value of the real-valued function with values from the value range restricted by the lower output variable limit and the upper output variable limit; and

determine an output that confirms a robustness of the network when the lowest possible value and the highest possible value lie within a predefined interval of permissible values.

12 . The device as recited in claim 11 , wherein the device has at least one memory for the input variable, and an output device, the input variable representing sensor data or the input variable representing variables that are measurable by a sensor by which sensor data are able to be predicted, and the output device is configured to output a signal, and the processor device is configured to determine the signal as a function of the output variable to which the artificial neural networks maps the input variable.

13 . The device as recited in claim 11 , wherein the device includes an input device, the input device being configured to communicate with a sensor in order to acquire sensor data, and the processor device is configured to determine the input variable as a function of the sensor data.

14 . A non-transitory computer-readable medium on which is stored a computer program including computer-readable instructions for training and/or verifying a robustness of an artificial neural network in which the artificial neural network is configured to determine an output variable, the instructions, when executed by a computer, causing the computer to perform the following steps:

predefining an input variable for the artificial neural network that has a plurality of dimensions, for each dimension of the input variable or for each dimension of an output of a linear layer of the artificial neural network without an activation function to which the input variable is mapped by the artificial neural network, performing:

determining an upper input variable limit for which a disturbance model by which the input variable is able to be mapped to a disturbed input variable has a highest possible value in the dimension, and

determining a lower input variable limit for which the disturbance variable model has a lowest possible value in the dimension;

for each dimension of the output variable, performing:

determining a lower output variable limit for the output variable with values from a value range restricted by the lower input variable limits and the upper variable limits, and

determining an upper output variable limit for the output variable with the values from the value range restricted by the upper input variable limits and the lower input variable limits;

determining a lowest possible value of a real-valued function with values from a value range restricted by the lower output variable limit and the upper output variable limit;

determining a highest possible value of the real-valued function with values from the value range restricted by the lower output variable limit and the upper output variable limit; and

determining an output that confirms a robustness of the network when the lowest possible value and the highest possible value lie within a predefined interval of permissible values.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 21, 2022
From: SCHMIDT, FRANK
To: ROBERT BOSCH GMBH
Reel/Frame 061498/0407 →
Priority Claims (1)
DE 10 2021 208 520.2 · Aug 5, 2021 · national
Continuity (1)
Related Publication 20230039379A1 · Feb 9, 2023
References Cited (7)
US 20200349673A1 · Yoo · 2020 [cited by examiner]
US 20220343641A1 · Runge · 2022 [cited by examiner]
Neto et al., NPL1 (“ANN-based intelligent control system for simultaneous feed disturbances rejection and product specification changes in extractive distillation process” Published Nov. 5, 2020 by ASME Publishing 13 Pa… [cited by examiner]
Bagheri et al., NPL2 (“Input-Output Analysis and Control Design Applied to a Linear Model of Spatially Developing Flows” Published 2009 by Elsevier Publishing 27 Pages (Year: 2009). [cited by examiner]
Wong et al., “Scaling Provable Adversarial Defenses,” Cornell University, 2018, pp. 1-22. <https://arxiv.org/abs/1805.12514> Downloaded Jul. 20, 2022. [cited by applicant]
Gowal et al., “On the Effectiveness of Interval Bound Propagation for Training Verifiably Robust Models,” Cornell University, 2019, pp. 1-16. <https://arxiv.org/abs/1810.12715> Downloaded Jul. 20, 2022. [cited by applicant]
Wong et al., “Provable Defenses Against Adversarial Examples via the Convex Outer Adversarial Polytope,” Proceedings of the 35th International Conference on Machine Learning, Stockholm, Sweden, PMLR 80, 2018, pp. 1-10. [cited by applicant]