214
v1v2 (latest)

Tight Robustness Certification Through the Convex Hull of 0\ell_0 Attacks

Main:8 Pages
10 Figures
Bibliography:2 Pages
3 Tables
Appendix:9 Pages
Abstract

Few-pixel attacks mislead a classifier by modifying a few pixels of an image. Their perturbation space is an 0\ell_0-ball, which is not convex, unlike p\ell_p-balls for p1p\geq1. However, existing local robustness verifiers typically scale by relying on linear bound propagation, which captures convex perturbation spaces. We show that the convex hull of an 0\ell_0-ball is the intersection of its bounding box and an asymmetrically scaled 1\ell_1-like polytope. The volumes of the convex hull and this polytope are nearly equal as the input dimension increases. We then show a linear bound propagation that precisely computes bounds over the convex hull and is significantly tighter than bound propagations over the bounding box or our 1\ell_1-like polytope. This bound propagation scales the state-of-the-art 0\ell_0 verifier on its most challenging robustness benchmarks by 1.24x-7.07x, with a geometric mean of 3.16.

View on arXiv
Comments on this paper