首个可迭代精化输入集的神经ODE形式化验证工具,提升安全性质验证精度。
TNODEV: Toolbox for Neural ODE Verification

- 集成反例检测与区间可达性算法,支持多策略输入集分裂
- 在MNIST分类器上验证结果优于NNV 2.0,对闭环系统验证有效
- 适合需要形式化保证的工业控制与自动驾驶决策系统研究者
神经常微分方程(neural ODE)在车联网物理系统控制器与自动化决策流程中的分类器等安全关键场景中受到关注,引发其行为是否可形式化验证的问题。现有工具仅提供一次可达性计算,缺乏输入集迭代精化,导致验证结论精度受限。本文提出TNODEV,首个集成反例检测、基于连续时间混合单调性的快速区间可达性后端、包含三种输入集分裂启发式策略的验证与精化循环,以及并行调度器的端到端形式化验证框架。该工具支持纯神经ODE、神经网络控制器闭环下的神经ODE及通用神经ODE(GNODE)的安全集包含性验证,安全集可为区间或目标分类标签诱导的半空间交集。我们在多个基准测试中评估了其在安全集包含与分类鲁棒性方面的表现,包括与NNV 2.0和CORA的直接可达性对比,以及在MNIST GNODE分类器上与NNV 2.0的验证性能对比。
原文摘要 · Abstract (English)
Neural ordinary differential equations (neural ODE) gained attention in safety critical settings such as continuous-time controllers for cyber-physical systems and classifiers integrated into automated decision pipelines, raising the question whether their behavior can be formally verified. Existing tools dedicated to neural ODE provide only a single reachability call without iterative input-set refinement, limiting the precision of their verdicts to whatever one reachability call can deliver. We present TNODEV, the first formal verifier for neural ODE that integrates a falsification checker, a fast interval-based reachability backend based on continuous-time mixed monotonicity, a verification and refinement loop with three input-set splitting heuristics, and a parallel scheduler in a single end-to-end pipeline. TNODEV supports safe-set inclusion verification on pure neural ODE, neural ODE in closed loop with a neural network controller and general neural ODE (GNODE), with the safe set specified either as an interval or as the half-space intersection induced by a target classification label. We evaluate TNODEV on a range of benchmarks across safe-set inclusion and classification-robustness properties, including a direct reachability comparison against NNV 2.0 and CORA and a verification comparison against NNV 2.0 on MNIST general neural ODE classifiers.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。