[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82923-en":3,"doc-seo-82923-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},82923,8796095461610,"Oliver","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Privacy-Preserving Robustness Verification for Neural Networks","Neural network verification and data privacy are inherently in tension: verification requires access to model parameters and inputs, while privacy regulations and intellectual property constraints restrict disclosure. SECURECROWN addresses this gap by enabling privacy-preserving neural network robustness verification using secure two-party computation under a semi-honest model. A model owner and data owner jointly compute certified robustness bounds while revealing only final results. The method removes branching in Linear Bound Propagation by converting conditional logic into continuous arithmetic and uses Newton–Raphson refinement to improve numerical stability, matching plaintext results and running from 0.1 to 200s across settings.","Privacy-Preserving Robustness Verification for Neural Networks  \nNianyun Song 1,2 Xiaokun Luan3 Yu Guo 1 Rongfang Bie 1 Meng Sun3 Xiyue Zhang*2  \n1 School of Artificial Intelligence, Beijing Key Laboratory of Artificial Intelligence for Education, Engineering Research Center of Intelligent Technology and Educational Application (Ministry of Education), Beijing Normal University,  \nBeijing, China  \n2 School of Computer Science, University of Bristol, Bristol, UK  \n3 School of Mathematical Sciences, Peking University, Beijing, China  \narXiv :2607 .0525 1v 1 [ cs .CR] 6 Jul 2026  \nAbstract  \nNeural network verification and data privacy are inherently in tension: verification demands full access to model parameters and input data, yet both are increasingly restricted by privacy regulations and intellectual property constraints. This tension has left robustness verification impractical in privacy-sensitive domains. In this work, we address this gap with SECURECROWN, the first framework for privacy-preserving neural network robustness verification. Built upon secure two-party computation (2PC), our framework enables a model owner and a data owner to jointly compute certified robustness bounds—revealing only the final result while provably protecting both parties’ private data under the semi-honest security model. A key challenge is securely computing the conditional operations in Linear Bound Propagation, where the data-dependent branching is incompatible with standard secure computation protocols. We eliminate branching by formulating conditional logic as continuous arithmetic operations. Additionally, we introduce a Newton–Raphson refinement method to improve numerical stability. Extensive analysis and experiments show that SECURECROWN strictly matches plaintext verification results, while completing in 0.1–200s across varied model sizesand communication settings (LAN/WAN), demonstrating the feasibility of privacy-preserving neural network verification.  \n1 INTRODUCTION  \nThe field of deep learning (DL) has experienced enormous growth recently, with deep neural networks (DNNs) now deployed in a variety of safety-critical applications, includ-  \n* Correspondence to XZ ([xiyue.zhang@bristol.ac.uk](xiyue.zhang@bristol.ac.uk))  \ning medical diagnosis [Litjens et al., 2017, Esteva et al., 2017] and healthcare [Esteva et al., 2019, Davenport and Kalakota, 2019] . In these domains, safety and robustness of DNNs are essential. However, DNNs are susceptible to perturbations in their inputs [Szegedy et al., 2014], such as noise and illumination variations [Goodfellow et al., 2015, Hendrycks and Dietterich, 2019] . To ensure DNN robustness with worst-case guarantees, significant progress in verification approaches [Wu et al., 2024, Wang et al., 2021, Singh et al., 2019] has been made, which can certify that a model’s prediction remains stable regardless of data noise or environmental changes.  \nDespite these advances, existing verification techniques assume centralized access to both model parameters and input data in plaintext. This assumption is often unrealistic in privacy-sensitive deployments. In practice, user data may be subject to strict privacy regulations, such as the General Data Protection Regulation (GDPR) [Voigt and Von dem Bussche, 2017] . Meanwhile, proprietary model parameters constitute valuable intellectual property and may not be disclosed to third parties. Thus, the standard verification setting, where both model and data are fully accessible, is incompatible with many privacy-regulated collaborative scenarios.  \nWe consider a two-party verification setting in which a model owner P0 holds a proprietary DNN, while a data owner P1 holds sensitive input data. We aim to verify the robustness of the model on the given input such that only the verification result is revealed, while both the model parameters and the input data remain private. Achieving this requires jointly performing robustness verification without exposing ei","cbCaik58OnyJ4lZj","https://ap.wps.com/l/cbCaik58OnyJ4lZj","pdf",502209,1,20,"English","en",105,"# Abstract\n# 1 Introduction\n## Deep learning robustness and safety-critical applications\n## Limitations of centralized verification\n## Two-party privacy-preserving verification setting\n## Challenges in secure implementation and numerical precision","[{\"question\":\"What problem does SECURECROWN aim to solve?\",\"answer\":\"It targets the incompatibility between neural network robustness verification and privacy/IP constraints, enabling certified robustness verification without revealing model parameters or sensitive inputs.\"},{\"question\":\"How does SECURECROWN preserve privacy during verification?\",\"answer\":\"It uses secure two-party computation so a model owner and a data owner jointly compute certified robustness bounds, disclosing only the final verification result under the semi-honest security model.\"},{\"question\":\"Why is conditional logic in Linear Bound Propagation challenging for secure computation, and how is it handled?\",\"answer\":\"Data-dependent branching conflicts with standard secure computation protocols. SECURECROWN removes branching by reformulating conditional operations as continuous arithmetic operations and also applies Newton–Raphson refinement to improve numerical stability.\"}]",1784183983,50,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"privacy-preserving-robustness-verification-for-neural-networks","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/privacy-preserving-robustness-verification-for-neural-networks/82923/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does SECURECROWN aim to solve?","Question",{"text":75,"@type":76},"It targets the incompatibility between neural network robustness verification and privacy/IP constraints, enabling certified robustness verification without revealing model parameters or sensitive inputs.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does SECURECROWN preserve privacy during verification?",{"text":80,"@type":76},"It uses secure two-party computation so a model owner and a data owner jointly compute certified robustness bounds, disclosing only the final verification result under the semi-honest security model.",{"name":82,"@type":73,"acceptedAnswer":83},"Why is conditional logic in Linear Bound Propagation challenging for secure computation, and how is it handled?",{"text":84,"@type":76},"Data-dependent branching conflicts with standard secure computation protocols. SECURECROWN removes branching by reformulating conditional operations as continuous arithmetic operations and also applies Newton–Raphson refinement to improve numerical stability.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,126,129,133],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":28,"slug":113},6,"Technology","technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":21,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":21,"doc_module":4,"doc_module_name":45,"category_name":127,"show_sort_weight":21,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":45,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":45,"category_name":135,"show_sort_weight":106,"slug":136},19,"General","general"]