🤖 AI Summary
This study addresses the challenge of efficiently verifying neural network robustness against simultaneous bit-flip faults across multiple weight parameters. To this end, we propose mBFV, a formal verification framework that introduces multi-parameter bound propagation to directly aggregate worst-case perturbation contributions, thereby circumventing combinatorial enumeration. Furthermore, mBFV incorporates a perturbation-position-based branch-and-bound strategy to effectively tighten verification bounds. Experimental results demonstrate that mBFV successfully verifies robustness against four simultaneous bit flips in large-scale networks comprising up to 1.15 million parameters. Compared with existing baseline methods, the proposed framework achieves significantly superior verification efficiency and scalability, establishing it as a practical solution for assessing fault tolerance in deep neural networks under multi-bit corruption scenarios.
📝 Abstract
Hardware faults can flip bits in the stored weights of a quantized neural network, potentially compromising its predictions. While such faults typically affect multiple parameters simultaneously, existing verifiers are limited to single-parameter perturbations due to the combinatorial explosion of possible flip locations in large networks. We present mBFV (m-BitFlip Verifier), an efficient verification framework that proves robustness against simultaneous bit flips across multiple parameters without explicitly enumerating these combinations. mBFV achieves this via a novel multi-parameter bound propagation technique that directly aggregates the m worst-case contributions. To further tighten these bounds, mBFV employs a branch-and-bound mechanism over perturbation locations, partitioning the potential flips to smaller groups of neurons. Evaluated on 625 instances, mBFV successfully verifies 293, significantly outperforming a prior single-parameter verifier (38 verified instances) and an exact mixed-integer linear programming baseline (0 verified instances). Notably, while these baselines are restricted to single-parameter flips on small networks (up to 13k parameters), mBFV scales to verify networks with up to 1.15M parameters against up to four simultaneous parameter flips.