Abstract
We present a method for verifying the robustness of neural network-based image classifiers against a large class of intensity perturbations that frequently occur in computer vision. These perturbations, or intensity inhomogeneities, can be modelled by a spatially varying, multiplicative transformation of the intensities by a bias field. We illustrate an encoding of bias field transformations into neural network operations to exploit neural network formal verification toolkits. We extend the toolkit VeriNet with the above encoding, GPU support, input-domain splitting and a symbolic interval propagation pre-processing step. Finally, we show that the resulting implementation, VeriNetBF, can analyse models with up to 11M tuneable parameters and 6.5M ReLU nodes trained on the CIFAR-10 ImageNet and NYU fastMRI datasets.
Original language | English |
---|---|
State | Published - 2021 |
Event | 32nd British Machine Vision Conference, BMVC 2021 - Virtual, Online Duration: 22 Nov 2021 → 25 Nov 2021 |
Conference
Conference | 32nd British Machine Vision Conference, BMVC 2021 |
---|---|
City | Virtual, Online |
Period | 22/11/21 → 25/11/21 |