Mini-Batch Robustness Verification of Deep Neural Networks
Saar Tzour-Shaday, Dana Drachsler-Cohen
Abstract
Neural network image classifiers are ubiquitous in many safety-critical applications. However, they are susceptible to adversarial attacks. To understand their robustness to attacks, many local robustness verifiers have been proposed to analyze ϵ -balls of inputs. Yet, existing verifiers introduce a long analysis time or lose too much precision, making them less effective for a large set of inputs. In this work, we propose a new approach to local robustness: group local robustness verification. The key idea is to leverage the similarity of the network computations of certain ϵ -balls to reduce the overall analysis time. We propose BaVerLy , a sound and complete verifier that boosts the local robustness verification of a set of ϵ -balls by dynamically constructing and verifying mini-batches. BaVerLy adaptively identifies successful mini-batch sizes, accordingly constructs mini-batches of ϵ -balls that have similar network computations, and verifies them jointly. If a mini-batch is verified, all its ϵ -balls are proven robust. Otherwise, one ϵ -ball is suspected as not being robust, guiding the refinement. BaVerLy leverages the analysis results to expedite the analysis of that ϵ -ball as well as the analysis of the mini-batch with the other ϵ -balls. We evaluate BaVerLy on fully connected and convolutional networks for MNIST and CIFAR-10. Results show that BaVerLy scales the common one by one verification by 2.3x on average and up to 4.1x, in which case it reduces the total analysis time from 24 hours to 6 hours.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3b5038a5-8a8a-469d-89b0-979ccd9a6ee9Builds on16
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov et al.S&P 2018 · 987 citations
- Formal Security Analysis of Neural Networks using Symbolic IntervalsShiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang et al.USENIX Security 2018 · 523 citations
- Beta-CROWN: Efficient Bound Propagation with Per-neuron Split Constraints for Neural Network Robustness VerificationShiqi Wang, Huan Zhang, Kaidi Xu, Xue Lin et al.NeurIPS 2021 · 359 citations
- Sparse and Imperceivable Adversarial AttacksFrancesco Croce, Matthias HeinICCV 2019 · 228 citations
- Globally-Robust Neural NetworksKlas Leino, Zifan Wang, Matt FredriksonICML 2021 · 150 citations
Related papers
- Boosting Few-Pixel Robustness Verification via Covering Verification DesignsYuval Shapira, Naor Wiesel, Shahar Shabelman, Dana Drachsler-CohenCAV 2024 · 2 citations
- Verification of Neural Networks' Global RobustnessAnan Kabaha, Dana Drachsler-CohenOOPSLA 2024 · 12 citations
- Probably Approximately Global Robustness CertificationPeter Blohm, Patrick Indri, Thomas Gärtner, Sagar MalhotraICML 2025
- Fast Geometric Projections for Local Robustness CertificationAymeric Fromherz, Klas Leino, Matt Fredrikson, Bryan Parno et al.ICLR 2021 · 34 citations
- LEVIS: Large Exact Verifiable Input Spaces for Neural NetworksMohamad Fares El Hajj Chehade, Wenting Li, Brian Wesley Bell, Russell Bent et al.ICML 2025
