Increasing the Confidence of Deep Neural Networks by Coverage Analysis
arXiv:2101.12100 · doi:10.1109/TSE.2022.3163682
Abstract
The great performance of machine learning algorithms and deep neural networks in several perception and control tasks is pushing the industry to adopt such technologies in safety-critical applications, as autonomous robots and self-driving vehicles. At present, however, several issues need to be solved to make deep learning methods more trustworthy, predictable, safe, and secure against adversarial attacks. Although several methods have been proposed to improve the trustworthiness of deep neural networks, most of them are tailored for specific classes of adversarial examples, hence failing to detect other corner cases or unsafe inputs that heavily deviate from the training samples. This paper presents a lightweight monitoring architecture based on coverage paradigms to enhance the model robustness against different unsafe inputs. In particular, four coverage analysis methods are proposed and tested in the architecture for evaluating multiple detection logics. Experimental results show that the proposed approach is effective in detecting both powerful adversarial examples and out-of-distribution inputs, introducing limited extra-execution time and memory requirements.
References in corpus (8)
- PyTorch: An Imperative Style, High-Performance Deep Learning Library
- Distilling the Knowledge in a Neural Network
- Explaining and Harnessing Adversarial Examples
- Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms
- Evasion Attacks against Machine Learning at Test Time
- MagNet and "Efficient Defenses Against Adversarial Attacks" are Not Robust to Adversarial Examples
- Detecting Adversarial Examples by Input Transformations, Defense Perturbations, and Voting
- AdvKnn: Adversarial Attacks On K-Nearest Neighbor Classifiers With Approximate Gradients
Cited by in corpus (4)
- On the Real-World Adversarial Robustness of Real-Time Semantic Segmentation Models for Autonomous Driving
- Defending From Physically-Realizable Adversarial Attacks Through Internal Over-Activation Analysis
- DeepCover: Advancing RNN Test Coverage and Online Error Prediction using State Machine Extraction
- On the Minimal Adversarial Perturbation for Deep Neural Networks with Provable Estimation Error