[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-81606-en":3,"doc-seo-81606-105":30,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},81606,34359740700684,"Finn","https://ap-avatar.wpscdn.com/avatar/1f400023980c374ae676?_k=1777273430885731487",8,"Research & Report","Lipschitz-Based Robustness Certification Under Floating-Point Execution","Lipschitz-based robustness certification bounds a neural network’s sensitivity using concrete numerical computation rather than symbolic reasoning, enabling scalable verification. Existing soundness proofs typically assume exact real arithmetic, while deployed models run in floating-point, creating a semantic gap. The work provides counterexamples where real-arithmetic certificates fail under floating-point execution, then develops a compositional theory for feed-forward ReLU networks under standard rounding-error models, including conditions for safe robustness and certificate degradation.","arXiv :2603 . 13334v 5 [ cs .LG] 10 Jul 2026  \nLipschitz-Based Robustness Certification Under Floating-Point Execution  \nTOBY MURRAY, University of Melbourne, Australia  \nLipschitz-based robustness certification bounds a network’s sensitivity through concrete numerical computation rather than symbolic reasoning, and so scales efficiently. It is increasingly used even where verifiable guarantees matter. Yet, as with most prior work on robustness certification and verification, soundness is typically proved against a semantic model assuming exact real arithmetic. Deployed networks instead execute in floating-point, creating a gap between certified properties and executed behaviour.  \nAs motivating evidence, we give counterexamples showing that real arithmetic robustness guarantees can fail under floating-point execution, even for previously verified certifiers. We then develop a formal, compositional theory relating real arithmetic Lipschitz-based sensitivity bounds to floating-point execution under standard rounding-error models for feed-forward ReLU networks. We derive sound conditions for floating-point robustness, including bounds on certificate degradation and sufficient conditions for the absence of overflow. We also give an efficient floating-point Gram iteration algorithm for Lipschitz bounds and prove that it never under-estimates the true norm. Separately, when a model is certified pre-deployment, we show how measuring its actual deviation against a high-precision execution can substantially reduce certificate degradation.  \nWe formalise the theory and its soundness, and implement an executable certifier, evaluated across dense networks spanning image, tabular, and many-class classification. To our knowledge, ours is the first method for soundly accounting for floating-point effects in Lipschitz-based robustness certification, and, done efficiently, the first floating-point-sound robustness checking procedure of any kind to certify models’ entire test sets—even those with 500,000 examples—while retaining enough precision to be practical.  \n1 Introduction  \nRobustness is an important property for helping to ensure the trustworthiness of neural network classifier outputs. Given a neural network 􀀣 produces output class ArgMax(􀀣(􀁇)) for input 􀁇 , we say that this answer is robust if the neural network would have output the same class for any nearby input 􀁇′ within distance 􀁙 of 􀁇 : ∀􀁇′. ∥􀁇 − 􀁇′ ∥ ≤ 􀁙 =⇒ ArgMax (􀀣(􀁇′)) = ArgMax (􀀣(􀁇)) .  \nA range of robustness-checking techniques have been developed. These include techniques that verify the robustness of neural network outputs using symbolic reasoning, for example via abstract interpretation over relational domains [47] or specialised solvers [27] . A closely related class of approaches applies abstract interpretation over lightweight numeric abstract domains, such as zonotope-and interval-based methods [46], in order to improve verification scalability at the expense of precision.  \nA separate class of approaches certify robustness via sensitivity analysis, computing Lipschitz or norm-based sensitivity bounds [37, 54] . The implementations of these methods are amenable to formal verification [50] . And because they rely on concrete numerical computation rather than symbolic reasoning, they enjoy scalability benefits: per-input certification is cheap enough to apply to models’ entire test sets, while the most advanced also scale to billion-parameter models [23] .  \nMost existing approaches to robustness certification and verification (except for a few robustness verifiers and abstract interpreters—see e.g. [46–48, 60]), assume the neural network executes with real arithmetic semantics. Deployed neural network implementations instead operate via floating-point arithmetic. This creates a semantic gap between the arithmetic semantics assumed by the verifier or certification procedure and the deployed execution semantics—a discrepancy that has recently been highlighted as a cen","cbCaivSdB9rIs3ZE","https://ap.wps.com/l/cbCaivSdB9rIs3ZE","pdf",1111350,4,1,34,"English","en",105,"# Introduction\n## Robustness property and certification approaches\n## Semantic gap between real and floating-point arithmetic\n# Method overview and main contributions","[{\"question\":\"How is certificate quality maintained and evaluated in practice?\",\"answer\":\"The approach includes an efficient floating-point Gram iteration algorithm for Lipschitz bounds without under-estimating the true norm. Additionally, for pre-deployed models, it shows how measuring deviation via high-precision execution can substantially reduce certificate degradation, and it implements an executable certifier evaluated on dense classification networks.\"}]",1784174724,86,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":28},"lipschitz-based-robustness-certification-under-floating-point-execution","",{"@graph":36,"@context":77},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/lipschitz-based-robustness-certification-under-floating-point-execution/81606/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"How is certificate quality maintained and evaluated in practice?","Question",{"text":75,"@type":76},"The approach includes an efficient floating-point Gram iteration algorithm for Lipschitz bounds without under-estimating the true norm. Additionally, for pre-deployed models, it shows how measuring deviation via high-precision execution can substantially reduce certificate degradation, and it implements an executable certifier evaluated on dense classification networks.","Answer","https://schema.org",{"og:url":52,"og:type":79,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":81,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":84},[85,89,93,97,102,107,112,115,120,123,127],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},6,"Technology",50,"technology",{"id":108,"doc_module":4,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":113,"slug":114},30,"research-report",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},9,"Religion & Spirituality",20,"religion-spirituality",{"id":118,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":118,"slug":122},"World Cup","world-cup",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":124,"slug":126},10,"Lifestyle","lifestyle",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":98,"slug":130},19,"General","general"]