Scalable Neural Network Geometric Robustness Validation via Hölder Optimisation
Yanghao Zhang, Panagiotis Kouvaros, Alessio Lomuscio
Abstract
Neural Network (NN) verification methods provide local robustness guarantees for a NN in the dense perturbation space of an input. In this paper we introduce H 2 V, a method for the validation of local robustness of NNs against geometric perturbations. H 2 V uniquely employs a Hilbert space-filling construction to recast multi-dimensional problems into single-dimensional ones and Hölder optimisation, iteratively refining the estimation of the Hölder constant for constructing the lower bound. In common with current methods, Hölder optimisation might theoretically converge to a local minimum, thereby resulting in a robustness result being incorrect. However, we here identify conditions for H 2 V to be provably sound, and show experimentally that even outside the soundness conditions, the risk of incorrect results can be minimised by introducing appropriate heuristics in the global optimisation procedure. Indeed, we found no incorrect results validated by H 2 V on a large set of benchmarks from SoundnessBench and VNN-COMP. To assess the scalability of the approach, we report the results obtained on large NNs ranging from Resnet34 to Resnet152 and vision transformers. These point to state-of-the-art scalability of the approach when validating the local robustness of large NNs against geometric perturbations on the ImageNet dataset. Beyond image tasks, we show that the method's scalability enables for the first time the robustness validation of large-scale 3D-NNs in video classification tasks against geometric perturbations for long-sequence input frames on Kinetics/UCF101 datasets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6514a78b-a72a-4c54-a6e1-b62b8a0d02adBuilds on11
- AI2: Safety and Robustness Certification of Neural Networks with Abstract InterpretationTimon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov et al.S&P 2018 · 987 citations
- Automatic Perturbation Analysis for Scalable Certified Robustness and BeyondKaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang et al.NeurIPS 2020 · 415 citations
- Beta-CROWN: Efficient Bound Propagation with Per-neuron Split Constraints for Neural Network Robustness VerificationShiqi Wang, Huan Zhang, Kaidi Xu, Xue Lin et al.NeurIPS 2021 · 359 citations
- Fast and Complete: Enabling Complete Neural Network Verification with Rapid and Massively Parallel Incomplete VerifiersKaidi Xu, Huan Zhang, Shiqi Wang, Yihan Wang et al.ICLR 2021 · 250 citations
- Understanding The Robustness in Vision TransformersDaquan Zhou, Zhiding Yu, Enze Xie, Chaowei Xiao et al.ICML 2022 · 242 citations
Related papers
- Efficient Certification of Spatial RobustnessAnian Ruoss, Maximilian Baader, Mislav Balunovic, Martin T. VechevAAAI 2021 · 26 citations
- Verifying Structural Robustness of Deep Neural NetworkHai Duong, Thanh Tien Le, Lam Nguyen, ThanhVu NguyenFSE 2026
- Towards Verifying Robustness of Neural Networks Against A Family of Semantic PerturbationsJeet Mohapatra, Tsui-Wei Weng, Pin-Yu Chen, Sijia Liu et al.CVPR 2020
- Lipschitz Optimization for Formal Verification of HomographiesJean-Guillaume Durand, Panagiotis Kouvaros, Maxime Gariel, Alessio LomuscioCVPR 2026
- Provable Defense Against Geometric TransformationsRem Yang, Jacob Laurel, Sasa Misailovic, Gagandeep SinghICLR 2023 · 1 citation
