Interior-Point Vanishing Problem in Semidefinite Relaxations for Neural Network Verification

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Ueda, Ryota, Sato, Takami, Kobayashi, Ken, Nakata, Kazuhide
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866916791748395008
author Ueda, Ryota
Sato, Takami
Kobayashi, Ken
Nakata, Kazuhide
author_facet Ueda, Ryota
Sato, Takami
Kobayashi, Ken
Nakata, Kazuhide
contents Semidefinite programming (SDP) relaxation has emerged as a promising approach for neural network verification, offering tighter bounds than other convex relaxation methods for deep neural networks (DNNs) with ReLU activations. However, we identify a critical limitation in the SDP relaxation when applied to deep networks: interior-point vanishing, which leads to the loss of strict feasibility -- a crucial condition for the numerical stability and optimality of SDP. Through rigorous theoretical and empirical analysis, we demonstrate that as the depth of DNNs increases, the strict feasibility is likely to be lost, creating a fundamental barrier to scaling SDP-based verification. To address the interior-point vanishing, we design and investigate five solutions to enhance the feasibility conditions of the verification problem. Our methods can successfully solve 88% of the problems that could not be solved by existing methods, accounting for 41% of the total. Our analysis also reveals that the valid constraints for the lower and upper bounds for each ReLU unit are traditionally inherited from prior work without solid reasons, but are actually not only unbeneficial but also even harmful to the problem's feasibility. This work provides valuable insights into the fundamental challenges of SDP-based DNN verification and offers practical solutions to improve its applicability to deeper neural networks, contributing to the development of more reliable and secure systems with DNNs.
format Preprint
id arxiv_https___arxiv_org_abs_2506_10269
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Interior-Point Vanishing Problem in Semidefinite Relaxations for Neural Network Verification
Ueda, Ryota
Sato, Takami
Kobayashi, Ken
Nakata, Kazuhide
Machine Learning
Optimization and Control
90C22, 68T05
I.2.6; G.1.6
Semidefinite programming (SDP) relaxation has emerged as a promising approach for neural network verification, offering tighter bounds than other convex relaxation methods for deep neural networks (DNNs) with ReLU activations. However, we identify a critical limitation in the SDP relaxation when applied to deep networks: interior-point vanishing, which leads to the loss of strict feasibility -- a crucial condition for the numerical stability and optimality of SDP. Through rigorous theoretical and empirical analysis, we demonstrate that as the depth of DNNs increases, the strict feasibility is likely to be lost, creating a fundamental barrier to scaling SDP-based verification. To address the interior-point vanishing, we design and investigate five solutions to enhance the feasibility conditions of the verification problem. Our methods can successfully solve 88% of the problems that could not be solved by existing methods, accounting for 41% of the total. Our analysis also reveals that the valid constraints for the lower and upper bounds for each ReLU unit are traditionally inherited from prior work without solid reasons, but are actually not only unbeneficial but also even harmful to the problem's feasibility. This work provides valuable insights into the fundamental challenges of SDP-based DNN verification and offers practical solutions to improve its applicability to deeper neural networks, contributing to the development of more reliable and secure systems with DNNs.
title Interior-Point Vanishing Problem in Semidefinite Relaxations for Neural Network Verification
topic Machine Learning
Optimization and Control
90C22, 68T05
I.2.6; G.1.6
url https://arxiv.org/abs/2506.10269