FM2023Top-tier venue
Verifying Feedforward Neural Networks for Classification in Isabelle/HOL
Achim D. Brucker, Amy Stell
Abstract
Neural networks are being used successfully to solve classification problems, e.g., for detecting objects in images. It is well known that neural networks are susceptible if small changes applied to their input result in misclassification. Situations in which such a slight input change, often hardly noticeable by a human expert, results in a misclassification are called adversarial examples. If such inputs are used for adversarial attacks, they can be life-threatening if, for example, they occur in image classification systems used in autonomous cars or medical diagnosis. Systems employing neural networks, e.g., for safety or security-critical functionality, are a particular challenge for formal verification, which usually expects a formal specification (e.g., given as source code in a programming language for which a formal semantics exists). Such a formal specification does, per se, not exist for neural networks. In this paper, we address this challenge by presenting a formal embedding of feedforward neural networks into Isabelle/HOL and discussing desirable properties for neural networks in critical applications. Our Isabellebased prototype can import neural networks trained in TensorFlow, and we demonstrate our approach using a neural network trained for the classification of digits on a dot-matrix display.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f4b975c8-4036-4c96-b6d1-2dd438a10bfaBuilds on1
Related papers
- Analyzing Learning-Based Networked Systems with Formal VerificationArnaud Dethise, Marco Canini, Nina NarodytskaINFOCOM 2021 · 11 citations
- Reducing DNN Properties to Enable Falsification with Adversarial AttacksDavid Shriver, Sebastian G. Elbaum, Matthew B. DwyerICSE 2021 · 18 citations
- A Formally Verified Robustness Certifier for Neural NetworksJames Tobler, Hira Taqdees Syeda, Toby MurrayCAV 2025 · 1 citation
- DeepSaDe: Learning Neural Networks That Guarantee Domain Constraint SatisfactionKshitij Goyal, Sebastijan Dumancic, Hendrik BlockeelAAAI 2024 · 9 citations
- Quantitative Verification of Neural Networks and Its Security ApplicationsTeodora Baluta, Shiqi Shen, Shweta Shinde, Kuldeep S. Meel et al.CCS 2019 · 115 citations
