Verifying Robustness of Neural Networks with Tight Semidefinite Relaxations.

Saved in:
Bibliographic Details
Title: Verifying Robustness of Neural Networks with Tight Semidefinite Relaxations.
Authors: Azuma, Godai1,2 (AUTHOR) azuma@ise.aoyama.ac.jp, Kim, Sunyoung3 (AUTHOR) skim@ewha.ac.kr, Yamashita, Makoto2 (AUTHOR) Makoto.Yamashita@comp.isct.ac.jp
Source: Computational Optimization & Applications. May2026, Vol. 94 Issue 1, p41-72. 32p.
Subjects: Semidefinite programming, Quadratic programming, Artificial neural networks, Multilayer perceptrons
Abstract: For the verification of the safety of neural networks (NNs), Fazlyab et al. (2019) introduced a semidefinite programming (SDP) approach called DeepSDP. This formulation can be viewed as the dual of the SDP relaxation for a problem formulated as a quadratically constrained quadratic program (QCQP). While SDP relaxations of QCQPs generally provide approximate solutions with some gaps, this work focuses on tight SDP relaxations that provide exact solutions to the QCQP for single-layer NNs. Specifically, we analyze tightness conditions in three cases: (i) NNs with a single neuron, (ii) single-layer NNs with an ellipsoidal input set, and (iii) single-layer NNs with a rectangular input set. For NNs with a single neuron, we propose a condition that ensures the SDP admits a rank-1 solution to DeepSDP by transforming the QCQP into an equivalent two-stage problem leads to a solution collinear with a predetermined vector. For single-layer NNs with an ellipsoidal input set, the collinearity of solutions is proved via the Karush-Kuhn-Tucker condition in the two-stage problem. In case of single-layer NNs with a rectangular input set, we demonstrate that the tightness of DeepSDP can be reduced to the single-neuron NNs, case (i), if the weight matrix is a diagonal matrix. [ABSTRACT FROM AUTHOR]
Copyright of Computational Optimization & Applications is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 193495161
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Verifying Robustness of Neural Networks with Tight Semidefinite Relaxations.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Azuma%2C+Godai%22">Azuma, Godai</searchLink><relatesTo>1,2</relatesTo> (AUTHOR)<i> azuma@ise.aoyama.ac.jp</i><br /><searchLink fieldCode="AR" term="%22Kim%2C+Sunyoung%22">Kim, Sunyoung</searchLink><relatesTo>3</relatesTo> (AUTHOR)<i> skim@ewha.ac.kr</i><br /><searchLink fieldCode="AR" term="%22Yamashita%2C+Makoto%22">Yamashita, Makoto</searchLink><relatesTo>2</relatesTo> (AUTHOR)<i> Makoto.Yamashita@comp.isct.ac.jp</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Computational+Optimization+%26+Applications%22">Computational Optimization & Applications</searchLink>. May2026, Vol. 94 Issue 1, p41-72. 32p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Semidefinite+programming%22">Semidefinite programming</searchLink><br /><searchLink fieldCode="DE" term="%22Quadratic+programming%22">Quadratic programming</searchLink><br /><searchLink fieldCode="DE" term="%22Artificial+neural+networks%22">Artificial neural networks</searchLink><br /><searchLink fieldCode="DE" term="%22Multilayer+perceptrons%22">Multilayer perceptrons</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: For the verification of the safety of neural networks (NNs), Fazlyab et al. (2019) introduced a semidefinite programming (SDP) approach called DeepSDP. This formulation can be viewed as the dual of the SDP relaxation for a problem formulated as a quadratically constrained quadratic program (QCQP). While SDP relaxations of QCQPs generally provide approximate solutions with some gaps, this work focuses on tight SDP relaxations that provide exact solutions to the QCQP for single-layer NNs. Specifically, we analyze tightness conditions in three cases: (i) NNs with a single neuron, (ii) single-layer NNs with an ellipsoidal input set, and (iii) single-layer NNs with a rectangular input set. For NNs with a single neuron, we propose a condition that ensures the SDP admits a rank-1 solution to DeepSDP by transforming the QCQP into an equivalent two-stage problem leads to a solution collinear with a predetermined vector. For single-layer NNs with an ellipsoidal input set, the collinearity of solutions is proved via the Karush-Kuhn-Tucker condition in the two-stage problem. In case of single-layer NNs with a rectangular input set, we demonstrate that the tightness of DeepSDP can be reduced to the single-neuron NNs, case (i), if the weight matrix is a diagonal matrix. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Computational Optimization & Applications is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=193495161
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s10589-026-00765-5
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 32
        StartPage: 41
    Subjects:
      – SubjectFull: Semidefinite programming
        Type: general
      – SubjectFull: Quadratic programming
        Type: general
      – SubjectFull: Artificial neural networks
        Type: general
      – SubjectFull: Multilayer perceptrons
        Type: general
    Titles:
      – TitleFull: Verifying Robustness of Neural Networks with Tight Semidefinite Relaxations.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Azuma, Godai
      – PersonEntity:
          Name:
            NameFull: Kim, Sunyoung
      – PersonEntity:
          Name:
            NameFull: Yamashita, Makoto
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 05
              Text: May2026
              Type: published
              Y: 2026
          Identifiers:
            – Type: issn-print
              Value: 09266003
          Numbering:
            – Type: volume
              Value: 94
            – Type: issue
              Value: 1
          Titles:
            – TitleFull: Computational Optimization & Applications
              Type: main
ResultId 1