arXiv AI

NNV3: Expanding Neural Network Verification to New Architectures and Domains

NNV3 is the latest version of the Neural Network Verification tool, a MATLAB framework for formally verifying deep learning models and learning‑enabled cyber‑physical systems. It builds on earlier NNV releases by adding new Star‑set members—ModelStar for weight perturbation, VolumeStar for video and 3D volumetric inputs, and GraphStar for graph neural networks—alongside a probabilistic reachability mode and FairNNV for fairness certification. The update also introduces benchmarks in malware detection, power‑system modeling, medical imaging, variable‑length time series, and action recognition, and provides unified documentation and tutorials.

arXiv AI
Sep 25

Reachability-Based Formal Verification of Graph Neural Networks with Node and Edge Features

The paper extends the neural network verification framework to graph neural networks by introducing GraphStar sets, which model uncertainty over both node and edge features. This allows sound propagation of linear message‑passing operations and ReLU nonlinearities for GCN and GINE layers. Experiments on power system tasks (PF, OPF, CFA) and graph classification benchmarks (ENZYMES, PROTEINS) show that the method, called GNNV, yields tighter robustness guarantees than CORA and provides, for the first time, edge‑aware guarantees for GINE‑based models under joint node and edge perturbations.

By Anne M. Tumlin, Ben Wooding, Zhenxuan Shao, Diego Manzanas Lopez, Tyler Derr, Taylor T. Johnson
arXiv Machine Learning
Aug 14

Branch and Bound for Relational Verification of Neural Networks

arXiv:2608. 13118v1 Announce Type: new Abstract: Verification of neural networks against relational specifications, such as global robustness, is crucial for safety-critical applications of cyber-physical systems (CPS), given their increasing adoption of AI components.

By Kota Fukuda, Zhenya Zhang, Guanqin Zhang, Jianjun Zhao
arXiv Machine Learning
Jun 4

veriFIRE: an Industrial Case Study in Verifying Consistency Properties for a DNN-Based Wildfire Detection System

arXiv:2606. 04121v1 Announce Type: cross Abstract: We present our ongoing work on the veriFIRE project: a collaboration between industry and academia, aimed at applying verification to increase the reliability of a real-world, safety-critical system.

By Idan Refaeli, Maya Swisa, Itay Buchnik, Alon Zada, Guy Amir, Elad Mandelbaum, Ziv Freund, Guy Katz
arXiv Machine Learning
Jun 4

Certified Neural Approximations of Nonlinear Dynamics

arXiv:2505. 15497v3 Announce Type: replace Abstract: Neural networks hold great potential to act as approximate models of nonlinear dynamical systems, with the resulting neural approximations enabling verification and control of such systems.

By Frederik Baymler Mathiesen, Nikolaus Vertovec, Francesco Fabiano, Luca Laurenti, Alessandro Abate
arXiv AI
Jun 16

TNODEV: Toolbox for Neural ODE Verification

arXiv:2606. 16567v1 Announce Type: new Abstract: Neural ordinary differential equations (neural ODE) have started to appear in safety critical settings such as continuous-time controllers for cyber-physical systems and classifiers integrated into automated decision pipelines, raising the question of whether their behavior can be formally verified.

By Abdelrahman Sayed Sayed, Pierre-Jean Meyer, Mohamed Ghazel
arXiv Machine Learning
Aug 19

Certified but Private: Scalable Zero-Knowledge Proofs for Neural Network Guarantees

PANDA is a scalable system that uses zero‑knowledge proofs to certify the robustness and fairness of neural networks without revealing their private parameters. Built on the CROWN robustness framework, PANDA introduces a novel algorithm for proving linear relaxation bounds on non‑linear activation layers, producing lightweight proofs. The system can generate proofs for networks with over 2.9 million parameters in just five minutes and verify them in ten seconds, scaling polynomially with network size and enabling verification of models four orders of magnitude larger than prior ZKP‑based approaches.

By Youwei Zhong, Ben Merbaum, Timos Antonopoulos, Ning Luo, Charalampos Papamanthou, Katerina Sotiraki, Ruzica Piskac