Neural network verification has emerged as a useful technique for improving the reliability of deep learning systems. Current verification approaches primarily focus on local robustness, where perturbations are applied independently to each input element. Despite its common use, local robustness does not capture perturbations that exhibit coordinated relationships between input elements. Such perturbations arise from systematic transformations or filtering operations that preserve structural characteristics of the data. These perturbations, which we call “structural robustness”, represent a significant gap in existing verification capabilities.
This work focuses on structural robustness verification by formalizing two important classes of structured perturbations: linear position-invariant and linear position-varying. Those perturbations allow input elements to be modified in coordinated ways while preserving essential data structure. The main challenge is that structural perturbations cannot be directly expressed using standard interval-based specification formats that existing verification tools typically support.
To address this limitation, we introduce VeriS, a technique that reformulates structural robustness into standard local robustness problems by creating specialized subnetworks that encode perturbation behavior and integrates them with the original network architecture. VeriS enables verification across continuous spaces defined by structural robustness specifications while maintaining compatibility with existing verification tools. VeriS also introduces optimizations that significantly enhance verification performance such as converting complex operations into standard representations.
We implement and evaluate VeriS on benchmarks involving neural networks across three domains: image classification, audio processing, and healthcare applications. Our evaluation, which encompasses 5508 verification problems, demonstrates that VeriS successfully verifies 78% of structural robustness specifications when integrated with state-of-the-art verification tools. These results show that VeriS enables the verification of complex structural perturbations that were previously beyond the reach of existing neural network verification.
| Preprint (fse26maina-p1917-p-00b2aa2dda-176740-final.pdf) | 1.2MiB |
Tue 7 JulDisplayed time zone: Eastern Time (US & Canada) change
16:00 - 17:20 | RobustnessIdeas, Visions and Reflections / Research Papers at MB 3.445 Chair(s): Boqi Chen University of Ottawa | ||
16:00 20mTalk | PuzzleMark: Implicit Jigsaw Learning for Robust Code Dataset Watermarking in Neural Code Completion Models Research Papers Haocheng Huang Soochow University, Yuchen Chen Nanjing University, Weisong Sun Nanyang Technological University, Peizhuo Lv Nanyang Technological University, Yuan Xiao Nanjing University, Chunrong Fang Nanjing University, Yang Liu Nanyang Technological University, Xiaofang Zhang Soochow University Pre-print | ||
16:20 20mTalk | Fool Me If You Can: On the Robustness of Binary Code Similarity Detection Models against Semantics-preserving Transformations Research Papers Jiyong Uhm Sungkyunkwan University, Minseok Kim Sungkyunkwan University, Michalis Polychronakis Stony Brook University, Hyungjoon Koo Sungkyunkwan University Pre-print | ||
16:40 20mTalk | Verifying Structural Robustness of Deep Neural Network Research Papers Hai Duong George Mason University, Thanh Le National Institute of Information and Communications Technology (NICT), Lam Nguyen CMC Applied Technology Institute (CATI), ThanhVu Nguyen George Mason University Pre-print File Attached | ||
17:00 10mTalk | Towards Reliable Testing for Machine Unlearning Ideas, Visions and Reflections DOI Pre-print | ||