2020/04/21 by Matthew Wicker, Luca Laurenti, Wicker, Matthew +6 · 1 citation
Computer Science · Engineering · Mathematics · #Adversarial Robustness in Machine Learning #FOS: Computer and information sciences #Fault Detection and Control Systems #Machine Learning (cs.LG) #Machine Learning (stat.ML) #Machine Learning and Algorithms #cs.LG #stat.ML
paper · pdf · doi:10.48550/arxiv.2004.10281
UAI 2020; 13 pages, 5 figures, 1 table
openalex publication_date 2020/04/21 · arxiv created 2020/06/19 · arxiv updated 2020/06/22 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
We study probabilistic safety for Bayesian Neural Networks (BNNs) under adversarial input perturbations. Given a compact set of input points, T ⊆ ℝm, we study the probability w.r.t. the BNN posterior that all the points in T are mapped to the same region S in the output space. In particular, this can be used to evaluate the probability that a network sampled from the BNN is vulnerable to adversarial attacks. We rely on relaxation techniques from non-convex optimization to develop a method for computing a lower bound on probabilistic safety for BNNs, deriving explicit procedures for the case of interval and linear function propagation techniques. We apply our methods to BNNs trained on a regression task, airborne collision avoidance, and MNIST, empirically showing that our approach allows one to certify probabilistic safety of BNNs with millions of parameters.