Search arXivSearch

arXiv · 2607.03232

Fast SDP certification of neural networks : towards large multi-class datasets

Abstract

We present a new quadratic model for the certification problem in adversarial robustness, which simultaneously accounts for all possible target classes. Building on this model, we propose a novel semidefinite programming (SDP) relaxation for incomplete verification. A key advantage of our approach is that it certifies robustness in a single optimization, avoiding the need for a separate resolution per class. This yields a significant computational speed-up and enables scalability to large datasets with many classes. To further improve efficiency, we also propose an effective pruning strategy of active neurons, thus reducing the problem dimensionality and accelerating convergence.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Margot Boyer, Clément Rambour, Zacharie Alès, Amélie Lambert. 2026-07-03. Fast SDP certification of neural networks : towards large multi-class datasets. https://arxiv.org/abs/2607.03232

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Rooted Spider Embeddings and the Erd\H os-Sós Conjecture

Under a local density condition, we prove that every $k$-edge spider embeds at any prescribed center of degree at least $k$, unless all legs are even and the host graph has one of two specified structures. These structures contain complete bipartite subgraphs with prescribed neighborhoods. The proof uses path rerouting and three exchange lemmas that describe equality in neighborhood estimates. As a consequence, we recover the Erd\H os-Sós bound for all spiders.

math.CO

Random algebraic constructions for extremal and Ramsey problems

Building on Bukh's random algebraic method, we develop a framework for extremal and Ramsey problems involving apex hypergraphs. If $\mathcal{H}$ is a $(d-1)$-partite $(d-1)$-uniform hypergraph with $S$ edges and $\mathcal{H}(t)$ is obtained by adjoining $t$ vertices with common link $\mathcal{H}$, we prove that $\operatorname{ex}(n,\mathcal{H}(t))=Ω_{\mathcal{H}}(n^{d-1/S})$ for $t>9^{S+o_d(S)}$, which is best possible when $\mathcal{H}$ is Sidorenko. Our framework also yields sharper sided Zarankiewicz bounds, quantitative generalized Tur'an bounds, and diagonal multicolor Ramsey constructions. For each fixed $s\geq 2$ and $K\geq 3$, we further prove $\operatorname{r}_K(\mathcal K_{s,t};\mathcal K_n) =Θ_{s,t,K}((n/\log n)^s)$ for $t>9^{s+o(s)}$, extending a theorem of Alon and Rödl from factorial to exponential $t$. The main ingredients are interpolation on $m$-independent varieties, control of the dependencies imposed by symmetry, and linear spaces of forms whose nonzero members remain regular after a common algebraic slice. Limited edge independence then gives the spectral and local-density estimates needed for the Ramsey application.

math.CO

A note on vertex-critical induced subgraphs of shift graphs

Shift graphs, introduced by Erdős and Hajnal in 1964, form one of the simplest known non-recursive constructions of triangle-free graphs with arbitrarily large chromatic number. In this note, we identify a surprising property: for each integer $k \geq 1$, the smallest $k$-chromatic shift graph contains a \emph{unique} induced $k$-vertex-critical subgraph. We give an explicit description of this subgraph and prove its uniqueness. This provides a new family of vertex-critical triangle-free graphs of arbitrarily large chromatic number.

math.CO