English

Fast SDP certification of neural networks : towards large multi-class datasets

Combinatorics 2026-07-03 v1 Machine Learning

Abstract

We present a new quadratic model for the certification problem in adversarial robustness, which simultaneously accounts for all possible target classes. Building on this model, we propose a novel semidefinite programming (SDP) relaxation for incomplete verification. A key advantage of our approach is that it certifies robustness in a single optimization, avoiding the need for a separate resolution per class. This yields a significant computational speed-up and enables scalability to large datasets with many classes. To further improve efficiency, we also propose an effective pruning strategy of active neurons, thus reducing the problem dimensionality and accelerating convergence.

Keywords

Cite

@article{arxiv.2607.03232,
  title  = {Fast SDP certification of neural networks : towards large multi-class datasets},
  author = {Margot Boyer and Clément Rambour and Zacharie Alès and Amélie Lambert},
  journal= {arXiv preprint arXiv:2607.03232},
  year   = {2026}
}