Semidefinite Bound Propagation for Neural Network Verification with General Activations
Abstract
Linear bound propagation enables scalable neural network verification by propagating linear bounds through activation functions, but these bounds can lose tightness for general activations. The semidefinite bound propagation method SDP-CROWN strengthens these bounds while retaining efficient linear bound propagation, but its construction relies on a quadratic outer approximation derived from ReLU's piecewise linear structure. We extend semidefinite bound propagation to general activations using quadratic outer approximations derived from sector bounds and quadratic bounds. Our construction converts these constraints into optimizable linear bounds over ellipsoidal domains, which we refine recursively using the same semidefinite bound-propagation framework. The resulting linear bounds integrate directly into the standard bound-propagation recursion, enabling scalable verification against both and adversaries. Our experiments demonstrate substantial improvements in verification performance across all benchmarks with general activations. On representative benchmarks, our method improves verified accuracy over GenBaB from 12% to 57% on MNIST under perturbations and from 23% to 87% on CIFAR-10 under perturbations.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.