English

Parameterized Hardness of Zonotope Containment and Neural Network Verification

Computational Complexity 2026-05-19 v2 Discrete Mathematics Machine Learning Neural and Evolutionary Computing

Abstract

Neural networks with ReLU activations are a widely used model in machine learning. It is thus important to have a profound understanding of the properties of the functions computed by such networks. Recently, there has been increasing interest in the (parameterized) computational complexity of determining these properties. In this work, we close several gaps and resolve an open problem posted by Froese et al. [COLT '25] regarding the parameterized complexity of various problems related to network verification. In particular, we prove that deciding positivity (and thus surjectivity) of a function f ⁣:RdRf\colon\mathbb{R}^d\to\mathbb{R} computed by a 2-layer ReLU network is W[1]-hard when parameterized by dd. This result also implies that zonotope (non-)containment is W[1]-hard with respect to dd, a problem that is of independent interest in computational geometry, control theory, and robotics. Moreover, we show that approximating the maximum within any multiplicative factor in 2-layer ReLU networks, computing the LpL_p-Lipschitz constant for p(0,]p\in(0,\infty] in 2-layer networks, and approximating the LpL_p-Lipschitz constant in 3-layer networks are NP-hard and W[1]-hard with respect to dd. Notably, our hardness results are the strongest known so far and imply that the naive enumeration-based methods for solving these fundamental problems are all essentially optimal under the Exponential Time Hypothesis.

Keywords

Cite

@article{arxiv.2509.22849,
  title  = {Parameterized Hardness of Zonotope Containment and Neural Network Verification},
  author = {Vincent Froese and Moritz Grillo and Christoph Hertrich and Moritz Stargalla},
  journal= {arXiv preprint arXiv:2509.22849},
  year   = {2026}
}

Comments

20 pages, 5 figures, paper accepted at ICLR 2026