IP Library Granted Patent US 11,625,487
Granted Patent B2
US 11,625,487 · App. 16/256,267 · Granted Apr 11, 2023

Framework for certifying a lower bound on a robustness level of convolutional neural networks

Inventors: Pin-Yu Chen (Yorktown Heights, NY); Sijia Liu (Cambridge, MA); Akhilan Boopathy (Cambridge, MA); Tsui-Wei Weng (Cambridge, MA); Luca Daniel (Cambridge, MA)
Assignees: INTERNATIONAL BUSINESS MACHINES CORPORATION; MASSACHUSETTS INSTITUTE OF TECHNOLOGY
G06F21/577G06N3/0481G06N3/08G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,625,487
App. No.
16/256,267
Granted
Apr 11, 2023
Kind
B2
Abstract

A certification method, system, and computer program product include certifying an adversarial robustness of a convolutional neural network by deriving an analytic solution for a neural network output using an efficient upper bound and an efficient lower bound on an activation function and applying the analytic solution in computing a certified robustness.

Claims (34)

1. A computer-implemented certification method, the method comprising:

certifying a numerical level of robustness of various architectures of convolutional neutral networks (CNNs) with minimum adversarial distortion by:

deriving an analytic solution for a neural network output of the CNNs using an efficient block-wise linear bound on an activation function separately on non-linear operations in the CNNs,

wherein the efficient bound is derived using convolution operations.

2. The method of claim 1 , further comprising varying the activation function.

3. The method of claim 2 , wherein the activation function is varied until a numerical level of robustness of the neural network is within a predetermined threshold value.

4. The method of claim 1 , further comprising varying building blocks in the neural network.

5. The method of claim 4 , wherein the activation function is varied until a numerical level of robustness of the neural network is within a predetermined threshold value.

6. The method of claim 1 , further comprising varying both of the activation function and building blocks in the neural network.

7. The method of claim 1 , wherein the analytic solution is applied with a binary search.

8. The method of claim 1 , wherein an efficient upper bound as one of the efficient bound comprises a linear upper bound, and

wherein an efficient lower bound as one of the efficient bound comprises a linear lower bound.

9. The method of claim 1 , wherein the adversarial robustness is certified for a same input.

10. The method of claim 1 , embodied in a cloud-computing environment.

11. The method of claim 1 , further comprising computing the numerical level of the robustness a specific architecture of the CNNs based on the analytic solution,

wherein the analytic solution includes deriving, for each building block in the form of element-wise inequality equations, and then plugging in the corresponding bounds and back-propagate to a previous layer of the CNNs.

12. A computer program product for certification, the computer program product comprising a computer-readable storage medium having program instructions embodied therewith, the program instructions executable by a computer to cause the computer to perform:

certifying a numerical level of robustness of various architectures of convolutional neutral networks (CNNs) with minimum adversarial distortion by:

deriving an analytic solution for a neural network output of the CNNs using an efficient block-wise linear bound on an activation function separately on non-linear operations in the CNNs,

wherein the efficient bound is derived using convolution operations.

13. The computer program product of claim 12 , further comprising varying the activation function.

14. The computer program product of claim 13 , wherein the activation function is varied until a certified robustness of the neural network is within a predetermined threshold value.

15. The computer program product of claim 12 , further comprising varying building blocks in the neural network.

16. The computer program product of claim 15 , wherein the activation function is varied until a certified robustness of the neural network is within a predetermined threshold value.

17. The computer program product of claim 12 , further comprising varying both of the activation function and building blocks in the neural network.

18. The computer program product of claim 12 , wherein the analytic solution is applied with a binary search.

19. The computer program product of claim 12 , wherein an efficient upper bound as one of the efficient bound comprises a linear upper bound, and

wherein an efficient lower bound as one of the efficient bound comprises a linear lower bound.

20. A certification system, the system comprising:

a processor, and

a memory, the memory storing instructions to cause the processor to perform:

certifying a numerical level of robustness of various architectures of convolutional neutral networks (CNNs) with minimum adversarial distortion by:

deriving an analytic solution for a neural network output of the CNNs using an efficient block-wise linear bound on an activation function separately on non-linear operations in the CNNs,

wherein the efficient bound is derived using convolution operations.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2023
From: CHEN, PIN-YU; LIU, SIJIA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062418/0338 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2023
From: BOOPATHY, AKHILAN; WENG, TSUI-WEI; DANIEL, LUCA
To: MASSACHUSETTS INSTITUTE OF TECHNOLOGY
Reel/Frame 062418/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2022
From: CHEN, PIN-YU; LIU, SIJIA; BOOPATHY, AKHILAN; WENG, TSUI-WEI; DANIEL, LUCA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION; MASSACHUSETTS INSTITUTE OF TECHNOLOGY
Reel/Frame 060731/0816 →
Continuity (1)
Related Publication 20200242252A1 · Jul 30, 2020