Robustness guarantees for deep neural networks on videos

The widespread adoption of deep learning models places demands on their robustness. In this paper, we consider the robustness of deep neural networks on videos, which comprise both the spatial features of individual frames extracted by a convolutional neural network and the temporal dynamics between...

Celý popis

Podrobná bibliografie
Hlavní autoři: Kwiatkowska, M, Wu, M
Médium: Conference item
Jazyk:English
Vydáno: IEEE 2020
_version_ 1826284266841964544
author Kwiatkowska, M
Wu, M
author_facet Kwiatkowska, M
Wu, M
author_sort Kwiatkowska, M
collection OXFORD
description The widespread adoption of deep learning models places demands on their robustness. In this paper, we consider the robustness of deep neural networks on videos, which comprise both the spatial features of individual frames extracted by a convolutional neural network and the temporal dynamics between adjacent frames captured by a recurrent neural network. To measure robustness, we study the maximum safe radius problem, which computes the minimum distance from the optical flow sequence obtained from a given input to that of an adversarial example in the neighbourhood of the input. We demonstrate that, under the assumption of Lipschitz continuity, the problem can be approximated using finite optimisation via discretising the optical flow space, and the approximation has provable guarantees. We then show that the finite optimisation problem can be solved by utilising a two-player turn-based game in a cooperative setting, where the first player selects the optical flows and the second player determines the dimensions to be manipulated in the chosen flow. We employ an anytime approach to solve the game, in the sense of approximating the value of the game by monotonically improving its upper and lower bounds. We exploit a gradient-based search algorithm to compute the upper bounds, and the admissible A* algorithm to update the lower bounds. Finally, we evaluate our framework on the UCF101 video dataset.
first_indexed 2024-03-07T01:11:18Z
format Conference item
id oxford-uuid:8d1a6923-4cdf-4de0-a0db-d6bd5bca15e4
institution University of Oxford
language English
last_indexed 2024-03-07T01:11:18Z
publishDate 2020
publisher IEEE
record_format dspace
spelling oxford-uuid:8d1a6923-4cdf-4de0-a0db-d6bd5bca15e42022-03-26T22:49:04ZRobustness guarantees for deep neural networks on videosConference itemhttp://purl.org/coar/resource_type/c_5794uuid:8d1a6923-4cdf-4de0-a0db-d6bd5bca15e4EnglishSymplectic ElementsIEEE2020Kwiatkowska, MWu, MThe widespread adoption of deep learning models places demands on their robustness. In this paper, we consider the robustness of deep neural networks on videos, which comprise both the spatial features of individual frames extracted by a convolutional neural network and the temporal dynamics between adjacent frames captured by a recurrent neural network. To measure robustness, we study the maximum safe radius problem, which computes the minimum distance from the optical flow sequence obtained from a given input to that of an adversarial example in the neighbourhood of the input. We demonstrate that, under the assumption of Lipschitz continuity, the problem can be approximated using finite optimisation via discretising the optical flow space, and the approximation has provable guarantees. We then show that the finite optimisation problem can be solved by utilising a two-player turn-based game in a cooperative setting, where the first player selects the optical flows and the second player determines the dimensions to be manipulated in the chosen flow. We employ an anytime approach to solve the game, in the sense of approximating the value of the game by monotonically improving its upper and lower bounds. We exploit a gradient-based search algorithm to compute the upper bounds, and the admissible A* algorithm to update the lower bounds. Finally, we evaluate our framework on the UCF101 video dataset.
spellingShingle Kwiatkowska, M
Wu, M
Robustness guarantees for deep neural networks on videos
title Robustness guarantees for deep neural networks on videos
title_full Robustness guarantees for deep neural networks on videos
title_fullStr Robustness guarantees for deep neural networks on videos
title_full_unstemmed Robustness guarantees for deep neural networks on videos
title_short Robustness guarantees for deep neural networks on videos
title_sort robustness guarantees for deep neural networks on videos
work_keys_str_mv AT kwiatkowskam robustnessguaranteesfordeepneuralnetworksonvideos
AT wum robustnessguaranteesfordeepneuralnetworksonvideos