2018

Provable Robustness of ReLU networks via Maximization of Linear Regions

Croce, Francesco, Andriushchenko, Maksym, Hein, Matthias

Understand

It has been shown that neural network classifiers are not robust.

  • This raises concerns about their usage in safety-critical systems.
  • We propose in this paper a regularization scheme for ReLU networks which provably improves the robustness of the classifier by maximizing the linear regions of the classifier as well as the distance to the decision boundary.
  • Our techniques allow even to find the minimal adversarial perturbation for a fraction of test points for large networks.

Reading the bibliography…