Skip to main content

Showing 1–15 of 15 results for author: Patane, A

Searching in archive cs. Search in all archives.
.
  1. arXiv:2310.01951  [pdf, other

    cs.LG cs.AI

    Probabilistic Reach-Avoid for Bayesian Neural Networks

    Authors: Matthew Wicker, Luca Laurenti, Andrea Patane, Nicola Paoletti, Alessandro Abate, Marta Kwiatkowska

    Abstract: Model-based reinforcement learning seeks to simultaneously learn the dynamics of an unknown stochastic environment and synthesise an optimal policy for acting in it. Ensuring the safety and robustness of sequential decisions made through a policy in such an environment is a key challenge for policies intended for safety-critical scenarios. In this work, we investigate two complementary problems: f… ▽ More

    Submitted 3 October, 2023; originally announced October 2023.

    Comments: 47 pages, 10 figures. arXiv admin note: text overlap with arXiv:2105.10134

  2. arXiv:2306.13614  [pdf, other

    cs.LG cs.AI

    Adversarial Robustness Certification for Bayesian Neural Networks

    Authors: Matthew Wicker, Andrea Patane, Luca Laurenti, Marta Kwiatkowska

    Abstract: We study the problem of certifying the robustness of Bayesian neural networks (BNNs) to adversarial input perturbations. Given a compact set of input points $T \subseteq \mathbb{R}^m$ and a set of output points $S \subseteq \mathbb{R}^n$, we define two notions of robustness for BNNs in an adversarial setting: probabilistic robustness and decision robustness. Probabilistic robustness is the probabi… ▽ More

    Submitted 23 June, 2023; originally announced June 2023.

  3. arXiv:2306.10742  [pdf, other

    cs.LG stat.ML

    BNN-DP: Robustness Certification of Bayesian Neural Networks via Dynamic Programming

    Authors: Steven Adams, Andrea Patane, Morteza Lahijanian, Luca Laurenti

    Abstract: In this paper, we introduce BNN-DP, an efficient algorithmic framework for analysis of adversarial robustness of Bayesian Neural Networks (BNNs). Given a compact set of input points $T\subset \mathbb{R}^n$, BNN-DP computes lower and upper bounds on the BNN's predictions for all the points in $T$. The framework is based on an interpretation of BNNs as stochastic dynamical systems, which enables the… ▽ More

    Submitted 19 June, 2023; originally announced June 2023.

    Comments: To appear at ICML 2023

  4. arXiv:2304.10828  [pdf, other

    cs.LG cs.CY

    Individual Fairness in Bayesian Neural Networks

    Authors: Alice Doherty, Matthew Wicker, Luca Laurenti, Andrea Patane

    Abstract: We study Individual Fairness (IF) for Bayesian neural networks (BNNs). Specifically, we consider the $ε$-$δ$-individual fairness notion, which requires that, for any pair of input points that are $ε$-similar according to a given similarity metrics, the output of the BNN is within a given tolerance $δ>0.$ We leverage bounds on statistical sampling over the input space and the relationship between a… ▽ More

    Submitted 21 April, 2023; originally announced April 2023.

  5. arXiv:2207.06154  [pdf, other

    cs.LG cs.AI cs.CR

    On the Robustness of Bayesian Neural Networks to Adversarial Attacks

    Authors: Luca Bortolussi, Ginevra Carbone, Luca Laurenti, Andrea Patane, Guido Sanguinetti, Matthew Wicker

    Abstract: Vulnerability to adversarial attacks is one of the principal hurdles to the adoption of deep learning in safety-critical applications. Despite significant efforts, both practical and theoretical, training deep learning models robust to adversarial attacks is still an open problem. In this paper, we analyse the geometry of adversarial attacks in the large-data, overparameterized limit for Bayesian… ▽ More

    Submitted 28 February, 2024; v1 submitted 13 July, 2022; originally announced July 2022.

    Comments: arXiv admin note: text overlap with arXiv:2002.04359

  6. arXiv:2205.05763  [pdf, other

    cs.LG

    Individual Fairness Guarantees for Neural Networks

    Authors: Elias Benussi, Andrea Patane, Matthew Wicker, Luca Laurenti, Marta Kwiatkowska

    Abstract: We consider the problem of certifying the individual fairness (IF) of feed-forward neural networks (NNs). In particular, we work with the $ε$-$δ$-IF formulation, which, given a NN and a similarity metric learnt from data, requires that the output difference between any pair of $ε$-similar individuals is bounded by a maximum decision tolerance $δ\geq 0$. Working with a range of metrics, including t… ▽ More

    Submitted 11 May, 2022; originally announced May 2022.

  7. arXiv:2105.10134  [pdf, other

    cs.LG

    Certification of Iterative Predictions in Bayesian Neural Networks

    Authors: Matthew Wicker, Luca Laurenti, Andrea Patane, Nicola Paoletti, Alessandro Abate, Marta Kwiatkowska

    Abstract: We consider the problem of computing reach-avoid probabilities for iterative predictions made with Bayesian neural network (BNN) models. Specifically, we leverage bound propagation techniques and backward recursion to compute lower bounds for the probability that trajectories of the BNN model reach a given set of states while avoiding a set of unsafe states. We use the lower bounds in the context… ▽ More

    Submitted 19 June, 2021; v1 submitted 21 May, 2021; originally announced May 2021.

    Comments: Accepted, UAI 2021. 17 pages

  8. arXiv:2104.03180  [pdf, other

    cs.LG stat.ML

    Adversarial Robustness Guarantees for Gaussian Processes

    Authors: Andrea Patane, Arno Blaas, Luca Laurenti, Luca Cardelli, Stephen Roberts, Marta Kwiatkowska

    Abstract: Gaussian processes (GPs) enable principled computation of model uncertainty, making them attractive for safety-critical applications. Such scenarios demand that GP decisions are not only accurate, but also robust to perturbations. In this paper we present a framework to analyse adversarial robustness of GPs, defined as invariance of the model's decision to bounded perturbations. Given a compact su… ▽ More

    Submitted 7 April, 2021; originally announced April 2021.

    Comments: Submitted for publication

  9. arXiv:2102.05289  [pdf, other

    cs.LG cs.CR

    Bayesian Inference with Certifiable Adversarial Robustness

    Authors: Matthew Wicker, Luca Laurenti, Andrea Patane, Zhoutong Chen, Zheng Zhang, Marta Kwiatkowska

    Abstract: We consider adversarial training of deep neural networks through the lens of Bayesian learning, and present a principled framework for adversarial training of Bayesian Neural Networks (BNNs) with certifiable guarantees. We rely on techniques from constraint relaxation of non-convex optimisation problems and modify the standard cross-entropy error model to enforce posterior robustness to worst-case… ▽ More

    Submitted 22 February, 2021; v1 submitted 10 February, 2021; originally announced February 2021.

    Comments: Accepted AISTATS2021

  10. arXiv:2004.10281  [pdf, other

    cs.LG stat.ML

    Probabilistic Safety for Bayesian Neural Networks

    Authors: Matthew Wicker, Luca Laurenti, Andrea Patane, Marta Kwiatkowska

    Abstract: We study probabilistic safety for Bayesian Neural Networks (BNNs) under adversarial input perturbations. Given a compact set of input points, $T \subseteq \mathbb{R}^m$, we study the probability w.r.t. the BNN posterior that all the points in $T$ are mapped to the same region $S$ in the output space. In particular, this can be used to evaluate the probability that a network sampled from the BNN is… ▽ More

    Submitted 18 June, 2020; v1 submitted 21 April, 2020; originally announced April 2020.

    Comments: UAI 2020; 13 pages, 5 figures, 1 table

  11. arXiv:2002.04359  [pdf, other

    cs.LG stat.ML

    Robustness of Bayesian Neural Networks to Gradient-Based Attacks

    Authors: Ginevra Carbone, Matthew Wicker, Luca Laurenti, Andrea Patane, Luca Bortolussi, Guido Sanguinetti

    Abstract: Vulnerability to adversarial attacks is one of the principal hurdles to the adoption of deep learning in safety-critical applications. Despite significant efforts, both practical and theoretical, the problem remains open. In this paper, we analyse the geometry of adversarial attacks in the large-data, overparametrized limit for Bayesian Neural Networks (BNNs). We show that, in the limit, vulnerabi… ▽ More

    Submitted 24 June, 2020; v1 submitted 11 February, 2020; originally announced February 2020.

  12. arXiv:1912.00071  [pdf, other

    cs.LG stat.ML

    Safety Guarantees for Planning Based on Iterative Gaussian Processes

    Authors: Kyriakos Polymenakos, Luca Laurenti, Andrea Patane, Jan-Peter Calliess, Luca Cardelli, Marta Kwiatkowska, Alessandro Abate, Stephen Roberts

    Abstract: Gaussian Processes (GPs) are widely employed in control and learning because of their principled treatment of uncertainty. However, tracking uncertainty for iterative, multi-step predictions in general leads to an analytically intractable problem. While approximation methods exist, they do not come with guarantees, making it difficult to estimate their reliability and to trust their predictions. I… ▽ More

    Submitted 7 September, 2020; v1 submitted 29 November, 2019; originally announced December 2019.

    Comments: An earlier version of this work presented in NeurIPS-2019 Workshop on Safety and Robustness in Decision Making. A shorter (but otherwise equivalent) paper was accepted to the 59th Conference on Decision and Control (CDC2020)

  13. arXiv:1905.11876  [pdf, other

    stat.ML cs.LG

    Adversarial Robustness Guarantees for Classification with Gaussian Processes

    Authors: Arno Blaas, Andrea Patane, Luca Laurenti, Luca Cardelli, Marta Kwiatkowska, Stephen Roberts

    Abstract: We investigate adversarial robustness of Gaussian Process Classification (GPC) models. Given a compact subset of the input space $T\subseteq \mathbb{R}^d$ enclosing a test point $x^*$ and a GPC trained on a dataset $\mathcal{D}$, we aim to compute the minimum and the maximum classification probability for the GPC over all the points in $T$. In order to do so, we show how functions lower- and upper… ▽ More

    Submitted 11 March, 2020; v1 submitted 28 May, 2019; originally announced May 2019.

    Comments: 10 pages, 6 figures + Supplementary Material

  14. arXiv:1903.01980  [pdf, other

    cs.LG cs.CV stat.ML

    Statistical Guarantees for the Robustness of Bayesian Neural Networks

    Authors: Luca Cardelli, Marta Kwiatkowska, Luca Laurenti, Nicola Paoletti, Andrea Patane, Matthew Wicker

    Abstract: We introduce a probabilistic robustness measure for Bayesian Neural Networks (BNNs), defined as the probability that, given a test point, there exists a point within a bounded set such that the BNN prediction differs between the two. Such a measure can be used, for instance, to quantify the probability of the existence of adversarial examples. Building on statistical verification techniques for pr… ▽ More

    Submitted 5 March, 2019; originally announced March 2019.

    Comments: 9 pages, 6 figures

  15. arXiv:1809.06452  [pdf, other

    cs.LG stat.ML

    Robustness Guarantees for Bayesian Inference with Gaussian Processes

    Authors: Luca Cardelli, Marta Kwiatkowska, Luca Laurenti, Andrea Patane

    Abstract: Bayesian inference and Gaussian processes are widely used in applications ranging from robotics and control to biological systems. Many of these applications are safety-critical and require a characterization of the uncertainty associated with the learning model and formal guarantees on its predictions. In this paper we define a robustness measure for Bayesian inference against input perturbations… ▽ More

    Submitted 24 October, 2018; v1 submitted 17 September, 2018; originally announced September 2018.