Skip to content

Leveraging Over-Parameterization to Improve the Verifiability of Neural Networks

· 0 citations · 61 references

TL;DR

It is demonstrated that over-parameterization can be exploited not merely to enhance generalization, but also to mitigate neuron instability, one of the parameters affecting the efficiency of verification.

View source

Similar papers

Preprint Aug 2026

Uncovering the Limits of Proof Sharing for Neural Networks

This study shows that template subsumption rates can vary widely across scenarios, and presents FastCert, a novel technique for automatically distributing templates across neural network layers to increase performance impact, eschewing templates entirely if they are unlikely to produce a speedup.

Kanak Das, Shubham Ugare, B. E. Chang et al. · 0 citations

Diverge to Converge: Mutual Heterogeneous Learning for Robust Pruning

Mutual Heterogeneous Learning (MHL) is proposed, a framework enabling robust pruning via single-model inference that significantly outperforms single-model baselines in both adversarial robustness and corruption robustness, while maintaining competitive clean accuracy.

Jinhui Yu, Zikai Zhang, Khaled A. Harras et al. · 0 citations
Sep 2026

Toward Improving Stochastic Neural Network Robustness via Arbitrary Distribution Injection.

Adversarial attacks pose significant challenges to the security and robustness of deep-learning models. Stochastic neural networks (SNNs) have shown promising effectiveness in improving robustness by injecting stochastic noise into model activations, features, or weights. However, most existing SNN-based defenses rely on predefined distributional forms, such as Gaussian or Uniform. In real-world scenarios, data distributions are often non-Gaussian, skewed, or multimodal, which cannot be adequately captured by such fixed assumptions, thereby limiting the robustness of existing methods. To address this limitation, we propose a novel SNN named arbitrary distribution injection (ADI), which enables distribution modeling from nonpredefined, data-dependent distributions. In particular, we introduce a conditional stochastic feature mapping mechanism to model feature distributions, together with a theoretically grounded variance-regularization loss. Extensive experiments across diverse attack methods, datasets, modalities, and network architectures show that ADI achieves robustness improvements and promising generalization across the evaluated settings. Furthermore, detailed parameter analyses and feature-distribution visualizations provide deeper insights into the underlying mechanisms of ADI.

Rui Zhou, Hao Yang, Wen-Xu Wang et al. · 0 citations
Book Open access Aug 2026

Integrating Symbolic and Neural Mechanisms for Adversarially Robust Hyperdimensional Computing

Neuro-symbolic models may improve robustness by combining learned representations with structured composition, but their behavior under adversarial perturbation remains underexplored. We study a hybrid pipeline that fuses ViT features with classical descriptors through Hyperdimensional Computing (HDC). Across CIFAR10 (Subset), COIL100, and ETH80 under FGSM and Genetic Attack, ViT + Classical HDC degrades more gracefully than Pure HDC and ViT + HDC baselines. It achieves higher normalized AURC, lower attack-time decision margins, and larger gains from partial adversarial retraining. These results suggest that classical-neural fusion within HDC is a promising direction for robustness under the evaluated threat models.

Hamza Errahmouni Barkam, Salaar Saraj, Zhen Ye et al. · 0 citations
Jul 2026

Statistically Undetectable Backdoors in Deep Neural Networks

We show how an adversarial model trainer can plant backdoors in a large class of deep, feedforward neural networks. These backdoors are statistically undetectable in the white-box setting, meaning that the backdoored and honestly trained models are close in total variation distance, even given the full descriptions of the models (e.g., all of the weights). The backdoor provides access to invariance-based adversarial examples for every input, mapping distant inputs to unusually close outputs. However, without the backdoor, it is provably impossible (under standard cryptographic assumptions) to generate any such adversarial examples in polynomial time. Our theoretical and preliminary empirical findings demonstrate a fundamental power asymmetry between model trainers and model users.

Andrej Bogdanov, Alon Rosen, N. Vafa · 0 citations
Preprint Aug 2026

KAN-Robust-Bench: A Benchmark for Evaluating the Robustness of Kolmogorov-Arnold Networks

While machine learning models have demonstrated strong performance in many domains, these models have shown profound vulnerabilities when they are exposed to adversarial threats. While adversarial attacks fall into various categories, the most prominent category in research studies is evasion. In evasion attacks, the adversary generates perturbed versions of samples, which might not be observable by human eyes. These samples generally fool the machine learning models with high confidence. This phenomenon poses a significant security violation against machine learning models. In this paper, we investigate the certified and empirical robustness of various Kolmogorov-Arnold network architectures against strong evasion attacks. At first, we provide the mathematical foundations for randomized smoothing and interval bound propagation, and report the $\ell_2$-certified robustness of the models under randomized smoothing. After that, we systematically evaluate the robustness of various defended and undefended KAN models under FGSM, PGD, and C&W attacks in order to find out the optimal defense strategies and architectures.

Mohammad Meymani, R. Razavi-Far · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.