PatchCensor: Patch Robustness Certification for Transformers via Exhaustive Testing

نویسندگان

چکیده

In the past few years, Transformer has been widely adopted in many domains and applications because of its impressive performance. Vision (ViT), a successful well-known variant, attracts considerable attention from both industry academia thanks to record-breaking performance various vision tasks. However, ViT is also highly nonlinear like other classical neural networks could be easily fooled by natural adversarial perturbations. This limitation pose threat deployment real industrial environment, especially safety-critical scenarios. How improve robustness thus an urgent issue that needs addressed. Among all kinds robustness, patch defined as giving reliable output when random input domain perturbed. The perturbation corruption, such part camera lens being blurred. It distribution shift, object does not exist training data suddenly appearing camera. And worst case, there malicious attack aims fool prediction machine learning model arbitrarily modifying pixels within restricted region image. kind called physical it believed more than digital attack. Although some work on improvement Convolutional Neural Network (CNN), related studies counterpart are still at early stage usually much complex with far parameters. harder assess mention provide provable guarantee. this work, we propose PatchCensor, aiming certify applying exhaustive testing. We try guarantee considering Unlike empirical defenses against patches may adaptively breached, certified robust approaches can accuracy arbitrary attacks under certain conditions. existing certifications mostly based training, which often requires substantial efforts sacrifice normal samples. To bridge gap, PatchCensor seeks whole system detecting abnormal inputs instead asking give results for every input, inevitably compromise accuracy. Specifically, each tested voting over multiple inferences different mutated masks, where least one inference guaranteed exclude patch. seen complete-coverage testing, statistical test time. Our comprehensive evaluation demonstrates able achieve high ( e.g. 67.1% ImageNet 2%-pixel patches), significantly outperforming state-of-the-art techniques while achieving similar clean (81.8% ImageNet). same vanilla models. Meanwhile, our technique supports flexible configurations handle sizes simply changing masking strategy.

برای دانلود باید عضویت طلایی داشته باشید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Non-exhaustive Parity Testing

In this paper, some new approaches are presented to deal with the dilemma we are facing in using parity testing: (1) proposing a method of turning a parity untestable circuit into parity testable (2) presenting a scheme of replacing the exhaustive testing with nonexhaustive way. The parity testing may resume its spirits by using some new technologies including the way presented here. I. Parity ...

متن کامل

A method for testing current transformers

Several precise laboratory methods are now available for the determination of the ratio and phase angle of current transformers. 1 These, however, all require a considerable amount of special apparatus, such as carefully calibrated noninductive shunts and very sensitive alternating-current detectors, and are therefore not suited for use under shop or central-station conditions. The task of comp...

متن کامل

Generating pseudo-exhaustive vectors for external testing

In the past years special chips for external test have been successfully used for random pattern testing. In this paper a technique is presented to combine the advantages of such a low cost test with the advantages of pseudo-exhaustive testing, which are an enhanced fault coverage and a simplified test pattern generation. To achieve this goal two tasks are solved. Firstly, an algorithm is devel...

متن کامل

Iterative Exhaustive Pattern Generation for Logic Testing

Exhaustive pattern logic testing schemes provide all possible input patterns with respect to an output in the set of test patterns. This paper is concerned with the problem that arises when this is to be done simultaneously with respect to a number of outputs, using a single test set. More specijically, in this paper we describe an iterative procedure for generating a test set consisting of ndi...

متن کامل

Madras 7 Testing of Transformers

The structure of the circuit equivalent of a practical transformer is developed earlier. The performance parameters of interest can be obtained by solving that circuit for any load conditions. The equivalent circuit parameters are available to the designer of the transformers from the various expressions that he uses for designing the transformers. But for a user these are not available most of...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: ACM Transactions on Software Engineering and Methodology

سال: 2023

ISSN: ['1049-331X', '1557-7392']

DOI: https://doi.org/10.1145/3591870