Skip to results
MLSift
← Feed
routineAI Safety, Security & AlignmentSDP relaxation2607.03232

Fast SDP certification of neural networks : towards large multi-class datasets

Margot Boyer, Clément Rambour, Zacharie Alès, Amélie Lambert

math.CO stat.ML

Abstract

We present a new quadratic model for the certification problem in adversarial robustness, which simultaneously accounts for all possible target classes. Building on this model, we propose a novel semidefinite programming (SDP) relaxation for incomplete verification. A key advantage of our approach is that it certifies robustness in a single optimization, avoiding the need for a separate resolution per class. This yields a significant computational speed-up and enables scalability to large datasets with many classes. To further improve efficiency, we also propose an effective pruning strategy of active neurons, thus reducing the problem dimensionality and accelerating convergence.

Topics

Classified with taxonomy v2 on Sat, 5 Sept 2026.

The PDF is 1–3 MB. Open it in your browser's viewer, or load it here.

Open PDF