Author:
Ranzato Francesco,Zanella Marco
Abstract
We study the problem of formally and automatically verifying robustness properties of decision tree ensemble classifiers such as random forests and gradient boosted decision tree models. A recent stream of works showed how abstract interpretation, which is ubiquitously used in static program analysis, can be successfully deployed to formally verify (deep) neural networks. In this work we push forward this line of research by designing a general and principled abstract interpretation-based framework for the formal verification of robustness and stability properties of decision tree ensemble models. Our abstract interpretation-based method may induce complete robustness checks of standard adversarial perturbations and output concrete adversarial attacks. We implemented our abstract verification technique in a tool called silva, which leverages an abstract domain of not necessarily closed real hyperrectangles and is instantiated to verify random forests and gradient boosted decision trees. Our experimental evaluation on the MNIST dataset shows that silva provides a precise and efficient tool which advances the current state of the art in tree ensembles verification.
Publisher
Association for the Advancement of Artificial Intelligence (AAAI)
Cited by
19 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Reinforcement Learning with Neighborhood Search and Self-learned Rules;2024 IEEE 13th Data Driven Control and Learning Systems Conference (DDCLS);2024-05-17
2. Robustness verification of k-nearest neighbors by abstract interpretation;Knowledge and Information Systems;2024-04-26
3. Robustness Certification of k-Nearest Neighbors;2023 IEEE International Conference on Data Mining (ICDM);2023-12-01
4. Verifiable Learning for Robust Tree Ensembles;Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security;2023-11-15
5. Assessing One-Class and Binary Classification Approaches for Identifying Medicare Fraud;2023 IEEE 24th International Conference on Information Reuse and Integration for Data Science (IRI);2023-08