Scalable Polyhedral Verification of Recurrent Neural Networks
Wonryong Ryou, Jiayu Chen, Mislav Balunovic, Gagandeep Singh, Andrei Marian Dan, Martin T. Vechev
Abstract
Abstract We present a scalable and precise verifier for recurrent neural networks, calledProverbased on two novel ideas: (i) a method to compute a set of polyhedral abstractions for the non-convex and non-linear recurrent update functions by combining sampling, optimization, and Fermat’s theorem, and (ii) a gradient descent based algorithm for abstraction refinement guided by the certification problem that combines multiple abstractions for each neuron. UsingProver, we present the first study of certifying a non-trivial use case of recurrent neural networks, namely speech classification. To achieve this, we additionally develop custom abstractions for the non-linear speech preprocessing pipeline. Our evaluation shows thatProversuccessfully verifies several challenging recurrent models in computer vision, speech, and motion sensor data classification beyond the reach of prior work.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers10
- Efficiently Computing Local Lipschitz Constants of Neural Networks via Bound PropagationZhouxing Shi, Yihan Wang, Huan Zhang, J. Zico Kolter et al.NeurIPS 2022 · 73 citations
- Scalable verification of GNN-based job schedulersHaoze Wu, Clark W. Barrett, Mahmood Sharif, Nina Narodytska et al.OOPSLA 2022 · 10 citations
- A general construction for abstract interpretation of higher-order automatic differentiationJacob Laurel, Rem Yang, Shubham Ugare, Robert Nagel et al.OOPSLA 2022 · 9 citations
- Synthesizing Precise Static Analyzers for Automatic DifferentiationJacob Laurel, Siyuan Brant Qian, Gagandeep Singh, Sasa MisailovicOOPSLA 2023 · 8 citations
- Convex Hull Approximation for Activation FunctionsZhongkui Ma, Zihan Wang, Guangdong BaiOOPSLA 2025 · 2 citations
Builds on5
- Hidden Voice CommandsNicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang et al.USENIX Security 2016 · 672 citations
- Adversarial Training and Provable Defenses: Bridging the GapMislav Balunovic, Martin T. VechevICLR 2020 · 186 citations
- Certified Defense to Image Transformations via Randomized SmoothingMarc Fischer, Maximilian Baader, Martin T. VechevNeurIPS 2020 · 78 citations
- Fastened CROWN: Tightened Neural Network Robustness CertificatesZhaoyang Lyu, Ching-Yun Ko, Zhifeng Kong, Ngai Wong et al.AAAI 2020 · 70 citations
- Robustness Guarantees for Deep Neural Networks on VideosMin Wu, Marta KwiatkowskaCVPR 2020
Related papers
- PRIMA: general and precise neural network certification via scalable convex hull approximationsMark Niklas Müller, Gleb Makarchuk, Gagandeep Singh, Markus Püschel et al.POPL 2022 · 75 citations
- Tighter Truncated Rectangular Prism Approximation for RNN Robustness VerificationXingqi Lin, Liangyu Chen, Min Wu, Min Zhang et al.AAAI 2026
- ReLU Hull ApproximationZhongkui Ma, Jiaying Li, Guangdong BaiPOPL 2024 · 7 citations
- Complete Verification via Multi-Neuron Relaxation Guided Branch-and-BoundClaudio Ferrari, Mark Niklas Müller, Nikola Jovanovic, Martin T. VechevICLR 2022 · 117 citations
- The Octatope Abstract Domain for Verification of Neural NetworksStanley Bak, Taylor Dohmen, K. Subramani, Ashutosh Trivedi et al.FM 2023 · 5 citations
