VNN-LIB 2.0: Rigorous Foundations for Neural Network Verification
Ann Roy, Allen Antony, Andrea Gimelli, Matthew L. Daggitt
Abstract
Abstract Neural network verification is an active and rapidly maturing research area, with a growing ecosystem of solvers and tools. The VNN-LIB standard was introduced to support interoperability in this ecosystem, but Version 1.0 has several serious short-comings as a formal foundation: it lacks a precise syntax, semantics, and type system, offers limited expressivity, and relies on externally defined ONNX models whose semantics are informal and constantly evolving. The latter distinguishes VNN-LIB from established standards such as SMT-LIB, where queries are self-contained and have fixed semantics. In this paper we address these challenges by developing the theoretical foundations of VNN-LIB 2.0. Our key contribution is the introduction of the notion of a network theory , which abstractly characterises the minimal semantic interface required from a neural network model format. This abstraction enables VNN-LIB to be defined independently of any specific ONNX version while remaining compatible with evolving model representations. Building on this foundation, we present a formal syntax for a more expressive query language, a type system for it over the numeric domains provided by the network theory, and finally a formal semantics. To ensure internal consistency, the standard is mechanised in the Agda theorem prover. VNN-LIB 2.0 therefore provides robust and rigorous foundations for trustworthy neural network verification.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on7
- PyTorch 2: Faster Machine Learning Through Dynamic Python Bytecode Transformation and Graph CompilationJason Ansel, Edward Z. Yang, Horace He, Natalia Gimelshein et al.ASPLOS 2024 · 693 citations
- PRIMA: general and precise neural network certification via scalable convex hull approximationsMark Niklas Müller, Gleb Makarchuk, Gagandeep Singh, Markus Püschel et al.POPL 2022 · 75 citations
- ReluDiff: differential verification of deep neural networksBrandon Paulsen, Jingbo Wang, Chao WangICSE 2020 · 47 citations
- Scalable Verification of Quantized Neural NetworksThomas A. Henzinger, Mathias Lechner, Dorde ZikelicAAAI 2021 · 41 citations
- Provably Safe Neural Network Controllers via Differential Dynamic LogicSamuel Teuber, Stefan Mitsch, André PlatzerNeurIPS 2024 · 22 citations
Related papers
- The Octatope Abstract Domain for Verification of Neural NetworksStanley Bak, Taylor Dohmen, K. Subramani, Ashutosh Trivedi et al.FM 2023 · 5 citations
- The Rocq-NN-Roll Prover: Soundly Verifying Hyperproperties of Neural Networks in RocqAndrei Aleksandrov, Malte Jackisch, Kim VöllingerCAV 2026
- Generating and Checking DNN Verification ProofsHai Duong, ThanhVu Nguyen, Matthew DwyerNeurIPS 2025 · 9 citations
- Automated Safety Verification of Programs Invoking Neural NetworksMaria Christakis, Hasan Ferit Eniser, Holger Hermanns, Jörg Hoffmann et al.CAV 2021 · 10 citations
- Formal Reasoning About Confidence and Automated Verification of Neural NetworksMohammad Afzal, S. Akshay, Blaise Genest, Ashutosh GuptaFM 2026
