arXiv:2509.17413cs.LGcs.AI2025-09

用最坏情况的尾部风险评估神经网络安全性,兼顾不确定性与极端事件。

Distributionally Robust Safety Verification of Neural Networks via Worst-Case CVaR

  • 基于矩信息构建模糊集,结合最坏情况CVaR实现鲁棒安全验证
  • 在保持原方法计算结构的同时,显式考虑极端事件风险
  • 适用于控制闭环可达性分析与分类任务,适合高安全需求场景

在安全关键应用中,确保神经网络在输入不确定性下的安全性是一个基本挑战。本文在Fazlyab的二次约束(QC)与半定规划(SDP)框架基础上,通过将最坏情况条件风险价值(WC-CVaR)与固定均值和协方差的矩基模糊集结合,扩展至分布鲁棒且关注尾部风险的设定。所得条件仍可由半定规划检验,并显式刻画尾部风险。该方法拓展了输入不确定性几何覆盖范围,包括椭球、多面体和超平面,推广至尾部事件严重性至关重要的安全关键领域。通过数值实验展示了其在闭环控制系统的可达性分析与分类中的应用,表明风险水平ε在保守性与容忍尾部事件之间进行权衡,同时保留了先前QC/SDP方法的计算结构,适用于神经网络验证与鲁棒性分析。

原文摘要 · Abstract (English)

Ensuring the safety of neural networks under input uncertainty is a fundamental challenge in safety-critical applications. This paper builds on and expands Fazlyab's quadratic-constraint (QC) and semidefinite-programming (SDP) framework for neural network verification to a distributionally robust and tail-risk-aware setting by integrating worst-case Conditional Value-at-Risk (WC-CVaR) over a moment-based ambiguity set with fixed mean and covariance. The resulting conditions remain SDP-checkable and explicitly account for tail risk. This integration broadens input-uncertainty geometry-covering ellipsoids, polytopes, and hyperplanes-and extends applicability to safety-critical domains where tail-event severity matters. Applications to closed-loop reachability of control systems and classification are demonstrated through numerical experiments, illustrating how the risk level $\varepsilon$ trades conservatism for tolerance to tail events-while preserving the computational structure of prior QC/SDP methods for neural network verification and robustness analysis.

神经网络验证尾部风险鲁棒性安全关键

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。