{"publisher":"IOS Press","volume":325,"year":"2020","day":"24","oa":1,"language":[{"iso":"eng"}],"publication_status":"published","license":"https://creativecommons.org/licenses/by-nc/4.0/","external_id":{"isi":["000650971303002"],"arxiv":["1911.09032"]},"doi":"10.3233/FAIA200375","file":[{"date_created":"2020-09-21T07:12:32Z","content_type":"application/pdf","file_size":1692214,"success":1,"relation":"main_file","file_id":"8540","checksum":"80642fa0b6cd7da95dcd87d63789ad5e","date_updated":"2020-09-21T07:12:32Z","access_level":"open_access","file_name":"2020_ECAI_Henzinger.pdf","creator":"dernst"}],"acknowledgement":"We thank Christoph Lampert and Nikolaus Mayer for fruitful discussions. This research was supported in part by the Austrian Science Fund (FWF) under grants S11402-N23 (RiSE/SHiNE) and Z211-N23 (Wittgenstein Award) and the European Union’s Horizon 2020 research and innovation programme under the Marie SkłodowskaCurie grant agreement No. 754411.","page":"2433-2440","conference":{"location":"Santiago de Compostela, Spain","start_date":"2020-08-29","end_date":"2020-09-08","name":"ECAI: European Conference on Artificial Intelligence"},"date_updated":"2023-08-18T06:38:16Z","_id":"7505","publication":"24th European Conference on Artificial Intelligence","month":"02","type":"conference","user_id":"4359f0d1-fa6c-11eb-b949-802e58b17ae8","has_accepted_license":"1","article_processing_charge":"No","oa_version":"Published Version","date_created":"2020-02-21T16:44:03Z","file_date_updated":"2020-09-21T07:12:32Z","date_published":"2020-02-24T00:00:00Z","title":"Outside the box: Abstraction-based monitoring of neural networks","status":"public","ec_funded":1,"ddc":["000"],"author":[{"first_name":"Thomas A","id":"40876CD8-F248-11E8-B48F-1D18A9856A87","orcid":"0000-0002-2985-7724","full_name":"Henzinger, Thomas A","last_name":"Henzinger"},{"full_name":"Lukina, Anna","last_name":"Lukina","first_name":"Anna","id":"CBA4D1A8-0FE8-11E9-BDE6-07BFE5697425"},{"last_name":"Schilling","full_name":"Schilling, Christian","orcid":"0000-0003-3658-1065","id":"3A2F4DCE-F248-11E8-B48F-1D18A9856A87","first_name":"Christian"}],"citation":{"chicago":"Henzinger, Thomas A, Anna Lukina, and Christian Schilling. “Outside the Box: Abstraction-Based Monitoring of Neural Networks.” In 24th European Conference on Artificial Intelligence, 325:2433–40. IOS Press, 2020. https://doi.org/10.3233/FAIA200375.","mla":"Henzinger, Thomas A., et al. “Outside the Box: Abstraction-Based Monitoring of Neural Networks.” 24th European Conference on Artificial Intelligence, vol. 325, IOS Press, 2020, pp. 2433–40, doi:10.3233/FAIA200375.","apa":"Henzinger, T. A., Lukina, A., & Schilling, C. (2020). Outside the box: Abstraction-based monitoring of neural networks. In 24th European Conference on Artificial Intelligence (Vol. 325, pp. 2433–2440). Santiago de Compostela, Spain: IOS Press. https://doi.org/10.3233/FAIA200375","ieee":"T. A. Henzinger, A. Lukina, and C. Schilling, “Outside the box: Abstraction-based monitoring of neural networks,” in 24th European Conference on Artificial Intelligence, Santiago de Compostela, Spain, 2020, vol. 325, pp. 2433–2440.","ista":"Henzinger TA, Lukina A, Schilling C. 2020. Outside the box: Abstraction-based monitoring of neural networks. 24th European Conference on Artificial Intelligence. ECAI: European Conference on Artificial Intelligence, Frontiers in Artificial Intelligence and Applications, vol. 325, 2433–2440.","ama":"Henzinger TA, Lukina A, Schilling C. Outside the box: Abstraction-based monitoring of neural networks. In: 24th European Conference on Artificial Intelligence. Vol 325. IOS Press; 2020:2433-2440. doi:10.3233/FAIA200375","short":"T.A. Henzinger, A. Lukina, C. Schilling, in:, 24th European Conference on Artificial Intelligence, IOS Press, 2020, pp. 2433–2440."},"intvolume":" 325","tmp":{"short":"CC BY-NC (4.0)","image":"/images/cc_by_nc.png","legal_code_url":"https://creativecommons.org/licenses/by-nc/4.0/legalcode","name":"Creative Commons Attribution-NonCommercial 4.0 International (CC BY-NC 4.0)"},"isi":1,"department":[{"_id":"ToHe"}],"alternative_title":["Frontiers in Artificial Intelligence and Applications"],"quality_controlled":"1","abstract":[{"lang":"eng","text":"Neural networks have demonstrated unmatched performance in a range of classification tasks. Despite numerous efforts of the research community, novelty detection remains one of the significant limitations of neural networks. The ability to identify previously unseen inputs as novel is crucial for our understanding of the decisions made by neural networks. At runtime, inputs not falling into any of the categories learned during training cannot be classified correctly by the neural network. Existing approaches treat the neural network as a black box and try to detect novel inputs based on the confidence of the output predictions. However, neural networks are not trained to reduce their confidence for novel inputs, which limits the effectiveness of these approaches. We propose a framework to monitor a neural network by observing the hidden layers. We employ a common abstraction from program analysis - boxes - to identify novel behaviors in the monitored layers, i.e., inputs that cause behaviors outside the box. For each neuron, the boxes range over the values seen in training. The framework is efficient and flexible to achieve a desired trade-off between raising false warnings and detecting novel inputs. We illustrate the performance and the robustness to variability in the unknown classes on popular image-classification benchmarks."}],"project":[{"grant_number":"754411","_id":"260C2330-B435-11E9-9278-68D0E5697425","call_identifier":"H2020","name":"ISTplus - Postdoctoral Fellowships"},{"grant_number":"S 11407_N23","_id":"25832EC2-B435-11E9-9278-68D0E5697425","call_identifier":"FWF","name":"Rigorous Systems Engineering"},{"name":"The Wittgenstein Prize","call_identifier":"FWF","_id":"25F42A32-B435-11E9-9278-68D0E5697425","grant_number":"Z211"}]}