Lipschitz-Based Robustness Certification for Recurrent Neural Networks via Convex Relaxation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hamelbeck, Paul, Schiffer, Johannes
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916960974929920
author Hamelbeck, Paul
Schiffer, Johannes
author_facet Hamelbeck, Paul
Schiffer, Johannes
contents Robustness certification against bounded input noise or adversarial perturbations is increasingly important for deployment recurrent neural networks (RNNs) in safety-critical control applications. To address this challenge, we present RNN-SDP, a relaxation based method that models the RNN's layer interactions as a convex problem and computes a certified upper bound on the Lipschitz constant via semidefinite programming (SDP). We also explore an extension that incorporates known input constraints to further tighten the resulting Lipschitz bounds. RNN-SDP is evaluated on a synthetic multi-tank system, with upper bounds compared to empirical estimates. While incorporating input constraints yields only modest improvements, the general method produces reasonably tight and certifiable bounds, even as sequence length increases. The results also underscore the often underestimated impact of initialization errors, an important consideration for applications where models are frequently re-initialized, such as model predictive control (MPC).
format Preprint
id arxiv_https___arxiv_org_abs_2509_17898
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Lipschitz-Based Robustness Certification for Recurrent Neural Networks via Convex Relaxation
Hamelbeck, Paul
Schiffer, Johannes
Systems and Control
Machine Learning
Robustness certification against bounded input noise or adversarial perturbations is increasingly important for deployment recurrent neural networks (RNNs) in safety-critical control applications. To address this challenge, we present RNN-SDP, a relaxation based method that models the RNN's layer interactions as a convex problem and computes a certified upper bound on the Lipschitz constant via semidefinite programming (SDP). We also explore an extension that incorporates known input constraints to further tighten the resulting Lipschitz bounds. RNN-SDP is evaluated on a synthetic multi-tank system, with upper bounds compared to empirical estimates. While incorporating input constraints yields only modest improvements, the general method produces reasonably tight and certifiable bounds, even as sequence length increases. The results also underscore the often underestimated impact of initialization errors, an important consideration for applications where models are frequently re-initialized, such as model predictive control (MPC).
title Lipschitz-Based Robustness Certification for Recurrent Neural Networks via Convex Relaxation
topic Systems and Control
Machine Learning
url https://arxiv.org/abs/2509.17898