arXiv:2602.15756cs.CRcs.LG2026-02被引 1

证明逐层验证无法保证整体推理正确性

A Note on Non-Composability of Layerwise Approximate Verification for Neural Inference

  • 通过构造反例,展示逐层近似验证的逻辑漏洞
  • 任意网络都可被改造成对误差极度敏感的版本
  • 提醒验证系统设计者避免依赖逐层独立验证

针对浮点数据上的可验证(或零知识)机器学习推理,一种自然且非正式的方法是:'证明每一层的计算在容差δ内正确;因此最终输出是合理的推理结果'。本文通过一个简单反例指出,这种推论在一般情况下不成立:对于任意神经网络,均可构造出功能等价的网络,使得在个别层计算中被恶意选择的近似误差幅度足以将最终输出引导至预设的有界范围内任意位置。

原文摘要 · Abstract (English)

A natural and informal approach to verifiable (or zero-knowledge) ML inference over floating-point data is: ``prove that each layer was computed correctly up to tolerance $δ$; therefore the final output is a reasonable inference result''. This short note gives a simple counterexample showing that this inference is false in general: for any neural network, we can construct a functionally equivalent network for which adversarially chosen approximation-magnitude errors in individual layer computations suffice to steer the final output arbitrarily (within a prescribed bounded range).

可验证推理神经网络形式验证

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。