Verifying Robustness of Neural Networks with Tight Semidefinite Relaxations.
Saved in:
| Title: | Verifying Robustness of Neural Networks with Tight Semidefinite Relaxations. |
|---|---|
| Authors: | Azuma, Godai1,2 (AUTHOR) azuma@ise.aoyama.ac.jp, Kim, Sunyoung3 (AUTHOR) skim@ewha.ac.kr, Yamashita, Makoto2 (AUTHOR) Makoto.Yamashita@comp.isct.ac.jp |
| Source: | Computational Optimization & Applications. May2026, Vol. 94 Issue 1, p41-72. 32p. |
| Subjects: | Semidefinite programming, Quadratic programming, Artificial neural networks, Multilayer perceptrons |
| Abstract: | For the verification of the safety of neural networks (NNs), Fazlyab et al. (2019) introduced a semidefinite programming (SDP) approach called DeepSDP. This formulation can be viewed as the dual of the SDP relaxation for a problem formulated as a quadratically constrained quadratic program (QCQP). While SDP relaxations of QCQPs generally provide approximate solutions with some gaps, this work focuses on tight SDP relaxations that provide exact solutions to the QCQP for single-layer NNs. Specifically, we analyze tightness conditions in three cases: (i) NNs with a single neuron, (ii) single-layer NNs with an ellipsoidal input set, and (iii) single-layer NNs with a rectangular input set. For NNs with a single neuron, we propose a condition that ensures the SDP admits a rank-1 solution to DeepSDP by transforming the QCQP into an equivalent two-stage problem leads to a solution collinear with a predetermined vector. For single-layer NNs with an ellipsoidal input set, the collinearity of solutions is proved via the Karush-Kuhn-Tucker condition in the two-stage problem. In case of single-layer NNs with a rectangular input set, we demonstrate that the tightness of DeepSDP can be reduced to the single-neuron NNs, case (i), if the weight matrix is a diagonal matrix. [ABSTRACT FROM AUTHOR] |
| Copyright of Computational Optimization & Applications is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 193495161 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Verifying Robustness of Neural Networks with Tight Semidefinite Relaxations. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Azuma%2C+Godai%22">Azuma, Godai</searchLink><relatesTo>1,2</relatesTo> (AUTHOR)<i> azuma@ise.aoyama.ac.jp</i><br /><searchLink fieldCode="AR" term="%22Kim%2C+Sunyoung%22">Kim, Sunyoung</searchLink><relatesTo>3</relatesTo> (AUTHOR)<i> skim@ewha.ac.kr</i><br /><searchLink fieldCode="AR" term="%22Yamashita%2C+Makoto%22">Yamashita, Makoto</searchLink><relatesTo>2</relatesTo> (AUTHOR)<i> Makoto.Yamashita@comp.isct.ac.jp</i> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Computational+Optimization+%26+Applications%22">Computational Optimization & Applications</searchLink>. May2026, Vol. 94 Issue 1, p41-72. 32p. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22Semidefinite+programming%22">Semidefinite programming</searchLink><br /><searchLink fieldCode="DE" term="%22Quadratic+programming%22">Quadratic programming</searchLink><br /><searchLink fieldCode="DE" term="%22Artificial+neural+networks%22">Artificial neural networks</searchLink><br /><searchLink fieldCode="DE" term="%22Multilayer+perceptrons%22">Multilayer perceptrons</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: For the verification of the safety of neural networks (NNs), Fazlyab et al. (2019) introduced a semidefinite programming (SDP) approach called DeepSDP. This formulation can be viewed as the dual of the SDP relaxation for a problem formulated as a quadratically constrained quadratic program (QCQP). While SDP relaxations of QCQPs generally provide approximate solutions with some gaps, this work focuses on tight SDP relaxations that provide exact solutions to the QCQP for single-layer NNs. Specifically, we analyze tightness conditions in three cases: (i) NNs with a single neuron, (ii) single-layer NNs with an ellipsoidal input set, and (iii) single-layer NNs with a rectangular input set. For NNs with a single neuron, we propose a condition that ensures the SDP admits a rank-1 solution to DeepSDP by transforming the QCQP into an equivalent two-stage problem leads to a solution collinear with a predetermined vector. For single-layer NNs with an ellipsoidal input set, the collinearity of solutions is proved via the Karush-Kuhn-Tucker condition in the two-stage problem. In case of single-layer NNs with a rectangular input set, we demonstrate that the tightness of DeepSDP can be reduced to the single-neuron NNs, case (i), if the weight matrix is a diagonal matrix. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Computational Optimization & Applications is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=193495161 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1007/s10589-026-00765-5 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 32 StartPage: 41 Subjects: – SubjectFull: Semidefinite programming Type: general – SubjectFull: Quadratic programming Type: general – SubjectFull: Artificial neural networks Type: general – SubjectFull: Multilayer perceptrons Type: general Titles: – TitleFull: Verifying Robustness of Neural Networks with Tight Semidefinite Relaxations. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Azuma, Godai – PersonEntity: Name: NameFull: Kim, Sunyoung – PersonEntity: Name: NameFull: Yamashita, Makoto IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 05 Text: May2026 Type: published Y: 2026 Identifiers: – Type: issn-print Value: 09266003 Numbering: – Type: volume Value: 94 – Type: issue Value: 1 Titles: – TitleFull: Computational Optimization & Applications Type: main |
| ResultId | 1 |