Efficient Verification of Neural Networks Against LVM-Based Specifications
Harleen Hanspal, Alessio Lomuscio
Abstract
The deployment of perception systems based on neural networks in safety critical applications requires assurance on their robustness. Deterministic guarantees on network robustness require formal verification. Standard approaches for verifying robustness analyse invariance to analytically defined transformations, but not the diverse and ubiquitous changes involving object pose, scene viewpoint, occlusions, etc. To this end, we present an efficient approach for verifying specifications definable using Latent Variable Models that capture such diverse changes. The approach involves adding an invertible encoding head to the network to be verified, enabling the verification of latent space sets with minimal reconstruction overhead. We report verification experiments for three classes of proposed latent space specifications, each capturing different types of realistic input variations. Differently from previous work in this area, the proposed approach is relatively independent of input dimensionality and scales to a broad class of deep networks and real-world datasets by mitigating the inefficiency and decoder expressivity dependence in the present state-of-the-art.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d526981b-c004-478e-b048-121019559c40Cited by top-tier papers2
- Verifying Neural Network Robustness with Dual PerturbationsHai Duong, Lam Nguyen, Thanh Le, ThanhVu NguyenCVPR 2026 · 4 citations
- Lipschitz Optimization for Formal Verification of HomographiesJean-Guillaume Durand, Panagiotis Kouvaros, Maxime Gariel, Alessio LomuscioCVPR 2026
Builds on5
- Formal Security Analysis of Neural Networks using Symbolic IntervalsShiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang et al.USENIX Security 2018 · 523 citations
- Learning perturbation sets for robust machine learningEric Wong, J. Zico KolterICLR 2021 · 40 citations
- Principal Component FlowsEdmond Cunningham, Adam D. Cobb, Susmit JhaICML 2022 · 18 citations
- Robustness certification with generative modelsMatthew Mirman, Alexander Hägele, Pavol Bielik, Timon Gehr et al.PLDI 2021 · 14 citations
- Achieving Robustness in the Wild via Adversarial Mixing With Disentangled RepresentationsSven Gowal, Chongli Qin, Po-Sen Huang, A. Taylan Cemgil et al.CVPR 2020
Related papers
- Verifying Structural Robustness of Deep Neural NetworkHai Duong, Thanh Tien Le, Lam Nguyen, ThanhVu NguyenFSE 2026
- Efficient Certification of Spatial RobustnessAnian Ruoss, Maximilian Baader, Mislav Balunovic, Martin T. VechevAAAI 2021 · 26 citations
- VeriFlow: Modeling Distributions for Neural Network VerificationFaried Abu Zaid, Daniel Neider, Mustafa YalçinerAAAI 2026 · 1 citation
- Precise and Generalized Robustness Certification for Neural NetworksYuanyuan Yuan, Shuai Wang, Zhendong SuUSENIX Security 2023
- Towards Verifying Robustness of Neural Networks Against A Family of Semantic PerturbationsJeet Mohapatra, Tsui-Wei Weng, Pin-Yu Chen, Sijia Liu et al.CVPR 2020
