The Price Of Diagonal Multipliers In Neural Network Certificates
Abstract
Many semidefinite Lipschitz certificates for neural networks use diagonal multipliers on activation slope inequalities. We study their conservatism relative to a stated certificate class, using classical polytopic vertex-LMI ideas. For discrete-time neural dynamics, we derive necessary and sufficient vertex conditions for one-step quadratic incremental ℓ2-gain certificates over the independent-slope abstraction (class-exact). We connect this characterization to robustness margins; its layerwise counterpart is NP-hard to compute. A valid block-multiplier hierarchy contains the diagonal level and reaches the reference under strict quadratic-stability assumptions. For equilibrium models, fixed-point certificates dominate storage-based ones, and their diagonal level contains LBEN. For stability, the stated Lur’e–Postnikov-type Lyapunov family is at least as powerful as quadratic functions. We characterize its full strength over sector-bounded or monotone classes by necessary and sufficient vertex conditions with a constructive, decrease-preserving reduction; slope restrictions can permit strict improvement. Exact witnesses enclose the maximum diagonal/reference class price over 72 feedforward networks in [1.049355, 1.049357], and the maximum diagonal/full-block static class price over 828 equilibrium-model targets in [1.067848, 1.122833]. These are class-optimum enclosures; the separate 4.14% reduction from blocks of four compares returned feasible gains. Complete audits of twelve two-layer ReLU networks separate losses, with abstraction loss above 72% in one model. On two width-80 MNIST models, under a 60-second per-target budget, the original block policy loses to diagonal in certified accuracy at ϵ = 0.3.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.