Achieving Verified Robustness to Adversarial NLP Inputs
- ๐ค Speaker: Johannes Welbl (UCL)
- ๐ Date & Time: Friday 12 June 2020, 12:30 - 13:30
- ๐ Venue: https://meet.google.com/tgv-vods-pdk
Abstract
Neural networks are part of many contemporary NLP systems, yet their empirical success comes at the price of vulnerability to adversarial attacks, e.g. by synonym replacements or adversarial text deletion. While much previous work uses adversarial training or data augmentation to partially mitigate such brittleness, these methods are unlikely to actually find worst-case inputs due to the complexity of the search space arising from discrete text perturbations. In this talk, I will introduce an approach that tackles the problem of adversarial robustness from the opposite direction: we formally verify a system’s robustness against pre-defined classes of adversarial attacks. To this end we adopt Interval Bound Propagation and bound the consequences which input changes can have on model predictions, thus establishing bounds on worst-case adversarial attacks. We furthermore modify the conventional log-likelihood training objective to train models which can be efficiently verified in constant time—this would otherwise come with exponential search complexity. The resulting models have much improved verified accuracy, and come with an efficiently computable formal guarantee on worst case adversarial attacks.
Series This talk is part of the NLIP Seminar Series series.
Included in Lists
- All Talks (aka the CURE list)
- bld31
- Cambridge Centre for Data-Driven Discovery (C2D3)
- Cambridge Forum of Science and Humanities
- Cambridge Language Sciences
- Cambridge talks
- Chris Davis' list
- Computer Education Research
- Computing Education Research
- Department of Computer Science and Technology talks and seminars
- Graduate-Seminars
- Guy Emerson's list
- https://meet.google.com/tgv-vods-pdk
- Interested Talks
- Language Sciences for Graduate Students
- ndk22's list
- NLIP Seminar Series
- ob366-ai4er
- PMRFPS's
- rp587
- School of Technology
- Simon Baker's List
- Trust & Technology Initiative - interesting events
- yk449
Note: Ex-directory lists are not shown.
![[Talks.cam]](/static/images/talkslogosmall.gif)

Johannes Welbl (UCL)
Friday 12 June 2020, 12:30-13:30