Verifying Attention Robustness of Deep Neural Networks Against Semantic Perturbations - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2023

Verifying Attention Robustness of Deep Neural Networks Against Semantic Perturbations

Résumé

It is known that deep neural networks (DNNs) classify an input image by paying particular attention to certain specific pixels; a graphical representation of the magnitude of attention to each pixel is called a saliency-map. Saliency-maps are used to check the validity of the classification decision basis, e.g., it is not a valid basis for classification if a DNN pays more attention to the background rather than the subject of an image. Semantic perturbations can significantly change the saliencymap. In this work, we propose the first verification method for attention robustness, i.e., the local robustness of the changes in the saliency-map against combinations of semantic perturbations. Specifically, our method determines the range of the perturbation parameters (e.g., the brightness change) that maintains the difference between the actual saliency-map change and the expected saliency-map change below a given threshold value. Our method is based on activation region traversals, focusing on the outermost robust boundary for scalability on larger DNNs. We empirically evaluate the effectiveness and performance of our method on DNNs trained on popular image classification datasets.
Fichier principal
Vignette du fichier
nfm2023.pdf (4.81 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-04249934 , version 1 (19-10-2023)

Licence

Paternité

Identifiants

Citer

Satoshi Munakata, Caterina Urban, Haruki Yokoyama, Koji Yamamoto, Kazuki Munakata. Verifying Attention Robustness of Deep Neural Networks Against Semantic Perturbations. 15th International Symposium on NASA Formal Methods (NFM 2023), May 2023, Houston (TX), United States. pp.37-61, ⟨10.1007/978-3-031-33170-1_3⟩. ⟨hal-04249934⟩
20 Consultations
4 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More