Towards Verifying Neural Networks Against Multi-Parameter Bit-Flip Perturbations

📅 2026-10-06
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge of efficiently verifying neural network robustness against simultaneous bit-flip faults across multiple weight parameters. To this end, we propose mBFV, a formal verification framework that introduces multi-parameter bound propagation to directly aggregate worst-case perturbation contributions, thereby circumventing combinatorial enumeration. Furthermore, mBFV incorporates a perturbation-position-based branch-and-bound strategy to effectively tighten verification bounds. Experimental results demonstrate that mBFV successfully verifies robustness against four simultaneous bit flips in large-scale networks comprising up to 1.15 million parameters. Compared with existing baseline methods, the proposed framework achieves significantly superior verification efficiency and scalability, establishing it as a practical solution for assessing fault tolerance in deep neural networks under multi-bit corruption scenarios.
📝 Abstract
Hardware faults can flip bits in the stored weights of a quantized neural network, potentially compromising its predictions. While such faults typically affect multiple parameters simultaneously, existing verifiers are limited to single-parameter perturbations due to the combinatorial explosion of possible flip locations in large networks. We present mBFV (m-BitFlip Verifier), an efficient verification framework that proves robustness against simultaneous bit flips across multiple parameters without explicitly enumerating these combinations. mBFV achieves this via a novel multi-parameter bound propagation technique that directly aggregates the m worst-case contributions. To further tighten these bounds, mBFV employs a branch-and-bound mechanism over perturbation locations, partitioning the potential flips to smaller groups of neurons. Evaluated on 625 instances, mBFV successfully verifies 293, significantly outperforming a prior single-parameter verifier (38 verified instances) and an exact mixed-integer linear programming baseline (0 verified instances). Notably, while these baselines are restricted to single-parameter flips on small networks (up to 13k parameters), mBFV scales to verify networks with up to 1.15M parameters against up to four simultaneous parameter flips.
Problem

Research questions and friction points this paper is trying to address.

neural network verification
bit-flip perturbations
quantized neural networks
hardware faults
multi-parameter robustness
Innovation

Methods, ideas, or system contributions that make the work stand out.

Multi-parameter bound propagation
Bit-flip perturbation
Branch-and-bound
Neural network verification
Quantized neural networks
🔎 Similar Papers
No similar papers found.
H
Hai Duong
George Mason University, Fairfax, VA, USA
Thanh Le
Thanh Le
Wireless System Laboratory - NICT
reinforcement learningwireless networks
H
Ho Nguyen
George Mason University, Fairfax, VA, USA
T
ThanhVu Nguyen
George Mason University, Fairfax, VA, USA