{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,19]],"date-time":"2025-09-19T09:32:25Z","timestamp":1758274345025,"version":"3.40.3"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031453281"},{"type":"electronic","value":"9783031453298"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-45329-8_18","type":"book-chapter","created":{"date-parts":[[2023,10,21]],"date-time":"2023-10-21T18:02:40Z","timestamp":1697911360000},"page":"380-400","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["An Automata-Theoretic Approach to\u00a0Synthesizing Binarized Neural Networks"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-1478-9144","authenticated-orcid":false,"given":"Ye","family":"Tao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2315-1704","authenticated-orcid":false,"given":"Wanwei","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0581-2679","authenticated-orcid":false,"given":"Fu","family":"Song","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1171-7061","authenticated-orcid":false,"given":"Zhen","family":"Liang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0637-8744","authenticated-orcid":false,"given":"Ji","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongxu","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,10,22]]},"reference":[{"key":"18_CR1","doi-asserted-by":"crossref","unstructured":"Baluta, T., Shen, S., Shinde, S., Meel, K.S., Saxena, P.: Quantitative verification of neural networks and its security applications. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 1249\u20131264 (2019)","DOI":"10.1145\/3319535.3354245"},{"key":"18_CR2","unstructured":"Barrett, C., Stump, A., Tinelli, C., et al.: The SMT-lib standard: version 2.0. In: Proceedings of the 8th International Workshop on Satisfiability Modulo Theories (Edinburgh, UK), vol. 13, p. 14 (2010)"},{"issue":"5","key":"18_CR3","doi-asserted-by":"publisher","first-page":"3200","DOI":"10.1109\/TDSC.2021.3088661","volume":"19","author":"L Bu","year":"2022","unstructured":"Bu, L., Zhao, Z., Duan, Y., Song, F.: Taking care of the discretization problem: a comprehensive study of the discretization problem and a black-box adversarial attack in discrete integer domain. IEEE Trans. Dependable Secur. Comput. 19(5), 3200\u20133217 (2022)","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"18_CR4","doi-asserted-by":"crossref","unstructured":"Chen, G., et al.: Who is real bob? Adversarial attacks on speaker recognition systems. In: Proceedings of the 42nd IEEE Symposium on Security and Privacy (SP), pp. 694\u2013711 (2021)","DOI":"10.1109\/SP40001.2021.00004"},{"key":"18_CR5","unstructured":"Chen, G., Zhang, Y., Zhao, Z., Song, F.: QFA2SR: query-free adversarial transfer attacks to speaker recognition systems. In: Proceedings of the 32nd USENIX Security Symposium (2023)"},{"key":"18_CR6","doi-asserted-by":"crossref","unstructured":"Chen, Get al.: Towards understanding and mitigating audio adversarial examples for speaker recognition. IEEE Trans. Dependable Secur. Comput. 20(5), 3970\u20133987 (2022)","DOI":"10.1109\/TDSC.2022.3220673"},{"key":"18_CR7","doi-asserted-by":"crossref","unstructured":"Chen, G., Zhao, Z., Song, F., Chen, S., Fan, L., Liu, Y.: AS2T: arbitrary source-to-target adversarial attack on speaker recognition systems. IEEE Trans. Dependable Secur. Comput. 1\u201317 (2022)","DOI":"10.1109\/TDSC.2022.3189397"},{"key":"18_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"279","DOI":"10.1007\/978-3-030-03592-1_16","volume-title":"Verified Software. Theories, Tools, and Experiments","author":"C-H Cheng","year":"2018","unstructured":"Cheng, C.-H., N\u00fchrenberg, G., Huang, C.-H., Ruess, H.: Verification of binarized neural networks via inter-neuron factoring. In: Piskac, R., R\u00fcmmer, P. (eds.) VSTTE 2018. LNCS, vol. 11294, pp. 279\u2013290. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-03592-1_16"},{"key":"18_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"337","DOI":"10.1007\/978-3-540-78800-3_24","volume-title":"Tools and Algorithms for the Construction and Analysis of Systems","author":"L de Moura","year":"2008","unstructured":"de Moura, L., Bj\u00f8rner, N.: Z3: an efficient SMT solver. In: Ramakrishnan, C.R., Rehof, J. (eds.) TACAS 2008. LNCS, vol. 4963, pp. 337\u2013340. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-78800-3_24"},{"issue":"6","key":"18_CR10","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/MSP.2012.2211477","volume":"29","author":"L Deng","year":"2012","unstructured":"Deng, L.: The MNIST database of handwritten digit images for machine learning research. IEEE Signal Process. Mag. 29(6), 141\u2013142 (2012)","journal-title":"IEEE Signal Process. Mag."},{"key":"18_CR11","unstructured":"Dua, D., Graff, C.: UCI machine learning repository (2017). https:\/\/archive.ics.uci.edu\/ml"},{"key":"18_CR12","doi-asserted-by":"crossref","unstructured":"Eykholt, Ket al.: Robust physical-world attacks on deep learning visual classification. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1625\u20131634 (2018)","DOI":"10.1109\/CVPR.2018.00175"},{"key":"18_CR13","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1007\/978-3-030-45237-7_5","volume-title":"Tools and Algorithms for the Construction and Analysis of Systems","author":"M Giacobbe","year":"2020","unstructured":"Giacobbe, M., Henzinger, T.A., Lechner, M.: How many bits does it take to quantize your neural network? In: TACAS 2020, Part II. LNCS, vol. 12079, pp. 79\u201397. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-45237-7_5"},{"key":"18_CR14","unstructured":"GPT-4. https:\/\/openai.com\/product\/gpt-4"},{"key":"18_CR15","doi-asserted-by":"crossref","unstructured":"Guo, X., Wan, W., Zhang, Z., Zhang, M., Song, F., Wen, X.: Eager falsification for accelerating robustness verification of deep neural networks. In: Proceedings of the 32nd IEEE International Symposium on Software Reliability Engineering, pp. 345\u2013356 (2021)","DOI":"10.1109\/ISSRE52982.2021.00044"},{"key":"18_CR16","doi-asserted-by":"crossref","unstructured":"Henzinger, T.A., Lechner, M., Zikelic, D.: Scalable verification of quantized neural networks. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 35, pp. 3787\u20133795 (2021)","DOI":"10.1609\/aaai.v35i5.16496"},{"key":"18_CR17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2020.100270","volume":"37","author":"X Huang","year":"2020","unstructured":"Huang, X., et al.: A survey of safety and trustworthiness of deep neural networks: verification, testing, adversarial attack and defence, and interpretability. Comput. Sci. Rev. 37, 100270 (2020)","journal-title":"Comput. Sci. Rev."},{"key":"18_CR18","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"296","DOI":"10.1007\/978-3-030-32304-2_15","volume-title":"Static Analysis","author":"J Li","year":"2019","unstructured":"Li, J., Liu, J., Yang, P., Chen, L., Huang, X., Zhang, L.: Analyzing deep neural networks with symbolic propagation: towards higher precision and faster verification. In: Chang, B.-Y.E. (ed.) SAS 2019. LNCS, vol. 11822, pp. 296\u2013319. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-32304-2_15"},{"key":"18_CR19","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"248","DOI":"10.1007\/978-3-031-35257-7_15","volume-title":"Theoretical Aspects of Software Engineering","author":"Z Liang","year":"2023","unstructured":"Liang, Z., Ren, D., Liu, W., Wang, J., Yang, W., Xue, B.: Safety verification for neural networks based on set-boundary analysis. In: David, C., Sun, M. (eds.) TASE 2023. LNCS, vol. 13931, pp. 248\u2013267. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-35257-7_15"},{"key":"18_CR20","doi-asserted-by":"crossref","unstructured":"Liu, C., et al.: Algorithms for verifying deep neural networks. Found. Trends\u00ae Optim. 4(3\u20134), 244\u2013404 (2021)","DOI":"10.1561\/2400000035"},{"key":"18_CR21","doi-asserted-by":"publisher","first-page":"1365","DOI":"10.1007\/s11390-020-0546-7","volume":"35","author":"WW Liu","year":"2020","unstructured":"Liu, W.W., Song, F., Zhang, T.H.R., Wang, J.: Verifying ReLU neural networks from a model checking perspective. J. Comput. Sci. Technol. 35, 1365\u20131381 (2020)","journal-title":"J. Comput. Sci. Technol."},{"key":"18_CR22","unstructured":"L\u00f6sbrock, C.D.: Implementing an incremental solver for difference logic. Master\u2019s thesis, RWTH Aachen University (2018)"},{"key":"18_CR23","unstructured":"Nagel, M., Fournarakis, M., Amjad, R.A., Bondarenko, Y., Van Baalen, M., Blankevoort, T.: A white paper on neural network quantization. arXiv preprint arXiv:2106.08295 (2021)"},{"key":"18_CR24","doi-asserted-by":"crossref","unstructured":"Narodytska, N., Kasiviswanathan, S., Ryzhyk, L., Sagiv, M., Walsh, T.: Verifying properties of binarized deep neural networks. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 32 (2018)","DOI":"10.1609\/aaai.v32i1.12206"},{"key":"18_CR25","unstructured":"Narodytska, N., Zhang, H., Gupta, A., Walsh, T.: In search for a SAT-friendly binarized neural network architecture. In: International Conference on Learning Representations (2020)"},{"key":"18_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"354","DOI":"10.1007\/978-3-030-24258-9_25","volume-title":"Theory and Applications of Satisfiability Testing \u2013 SAT 2019","author":"A Shih","year":"2019","unstructured":"Shih, A., Darwiche, A., Choi, A.: Verifying binarized neural networks by Angluin-style learning. In: Janota, M., Lynce, I. (eds.) SAT 2019. LNCS, vol. 11628, pp. 354\u2013370. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-24258-9_25"},{"key":"18_CR27","unstructured":"Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556 (2014)"},{"issue":"9","key":"18_CR28","doi-asserted-by":"publisher","first-page":"5210","DOI":"10.1002\/int.22510","volume":"36","author":"F Song","year":"2021","unstructured":"Song, F., Lei, Y., Chen, S., Fan, L., Liu, Y.: Advanced evasion attacks and mitigations on practical ml-based phishing website classifiers. Int. J. Intell. Syst. 36(9), 5210\u20135240 (2021)","journal-title":"Int. J. Intell. Syst."},{"key":"18_CR29","unstructured":"Tao, Y., Liu, W., Song, F., Liang, Z., Wang, J., Zhu, H.: An automata-theoretic approach to synthesizing binarized neural networks (2023). https:\/\/songfu1983.github.io\/publications\/ATVA23full.pdf"},{"key":"18_CR30","unstructured":"FSD chip-tesla. https:\/\/en.wikichip.org\/wiki\/tesla_(car_company)\/fsd_chip"},{"key":"18_CR31","doi-asserted-by":"crossref","unstructured":"Zhang, P., et al.: White-box fairness testing through adversarial sampling. In: Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering, pp. 949\u2013960 (2020)","DOI":"10.1145\/3377811.3380331"},{"key":"18_CR32","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Song, F., Sun, J.: QEBVerif: quantization error bound verification of neural networks. In: Proceedings of the 35th International Conference on Computer Aided Verification, pp. 413\u2013437 (2023)","DOI":"10.1007\/978-3-031-37703-7_20"},{"key":"18_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1007\/978-3-030-81685-8_8","volume-title":"Computer Aided Verification","author":"Y Zhang","year":"2021","unstructured":"Zhang, Y., Zhao, Z., Chen, G., Song, F., Chen, T.: BDD4BNN: a BDD-based quantitative analysis framework for binarized neural networks. In: Silva, A., Leino, K.R.M. (eds.) CAV 2021, Part I. LNCS, vol. 12759, pp. 175\u2013200. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-81685-8_8"},{"issue":"3","key":"18_CR34","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3576043","volume":"32","author":"Y Zhang","year":"2023","unstructured":"Zhang, Y., Zhao, Z., Chen, G., Song, F., Chen, T.: Precise quantitative analysis of binarized neural networks: a BDD-based approach. ACM Trans. Softw. Eng. Methodol. 32(3), 1\u201351 (2023)","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"18_CR35","doi-asserted-by":"crossref","unstructured":"Zhang, Y., et al.: QVIP: an ILP-based formal verification approach for quantized neural networks. In: Proceedings of the 37th IEEE\/ACM International Conference on Automated Software Engineering, pp. 1\u201313 (2022)","DOI":"10.1145\/3551349.3556916"},{"key":"18_CR36","doi-asserted-by":"crossref","unstructured":"Zhao, Z., Chen, G., Wang, J., Yang, Y., Song, F., Sun, J.: Attack as defense: characterizing adversarial examples using robustness. In: Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA), pp. 42\u201355 (2021)","DOI":"10.1145\/3460319.3464822"},{"key":"18_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"449","DOI":"10.1007\/978-3-031-22308-2_20","volume-title":"Static Analysis","author":"Z Zhao","year":"2022","unstructured":"Zhao, Z., Zhang, Y., Chen, G., Song, F., Chen, T., Liu, J.: CLEVEREST: accelerating CEGAR-based neural network verification via adversarial attacks. In: Singh, G., Urban, C. (eds.) SAS 2022. LNCS, vol. 13790, pp. 449\u2013473. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-22308-2_20"},{"key":"18_CR38","doi-asserted-by":"crossref","unstructured":"Zheng, H., et al.: NeuronFair: interpretable white-box fairness testing through biased neuron identification. In: Proceedings of the 44th International Conference on Software Engineering, pp. 1519\u20131531 (2022)","DOI":"10.1145\/3510003.3510123"}],"container-title":["Lecture Notes in Computer Science","Automated Technology for Verification and Analysis"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-45329-8_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,10,21]],"date-time":"2023-10-21T18:04:34Z","timestamp":1697911474000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-45329-8_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031453281","9783031453298"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-45329-8_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"22 October 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ATVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Symposium on Automated Technology for Verification and Analysis","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Singapore","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Singapore","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 October 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 October 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"atva2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/atva-conference.org\/2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"115","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"30","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.05","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"9","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7 tool papers","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}